<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" nvd_xml_version="2.0" pub_date="2013-05-23T07:52:12" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
  <entry id="CVE-2007-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::linux_kernel_2.6.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::linux_kernel_2.6.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0001</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:59:47.033-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-03-05T16:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9560" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9560" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0085.html" xml:lang="en">RHSA-2007:0085</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223129" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223129</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017705" xml:lang="en">1017705</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22737" xml:lang="en">22737</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24300" xml:lang="en">24300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33031" xml:lang="en">33031</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9560" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9560" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:libwpd:libwpd_library:0.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:libwpd:libwpd_library:0.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:libwpd:libwpd_library:0.8.7"/>
        <cpe-lang:fact-ref name="cpe:/a:libwpd:libwpd_library:0.8.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:libwpd:libwpd_library:0.8.2</vuln:product>
      <vuln:product>cpe:/a:libwpd:libwpd_library:0.8.6</vuln:product>
      <vuln:product>cpe:/a:libwpd:libwpd_library:0.8.8</vuln:product>
      <vuln:product>cpe:/a:libwpd:libwpd_library:0.8.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0002</vuln:cve-id>
    <vuln:published-datetime>2007-03-16T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-03-19T08:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11535" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11535" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1339" xml:lang="en">ADV-2007-1339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1032" xml:lang="en">ADV-2007-1032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0976" xml:lang="en">ADV-2007-0976</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-437-1" xml:lang="en">USN-437-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017789" xml:lang="en">1017789</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23006" xml:lang="en">23006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/463033/100/0/threaded" xml:lang="en">20070316 rPSA-2007-0057-1 libwpd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0055.html" xml:lang="en">RHSA-2007:0055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:064" xml:lang="en">MDKSA-2007:064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:063" xml:lang="en">MDKSA-2007:063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml" xml:lang="en">GLSA-200704-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1270" xml:lang="en">DSA-1270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1268" xml:lang="en">DSA-1268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102863-1" xml:lang="en">102863</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=494122" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=494122</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.399659" xml:lang="en">SSA-2007-085-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200704-07.xml" xml:lang="en">GLSA-200704-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24906" xml:lang="en">24906</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24856" xml:lang="en">24856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24794" xml:lang="en">24794</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24613" xml:lang="en">24613</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24593" xml:lang="en">24593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24591" xml:lang="en">24591</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24588" xml:lang="en">24588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24581" xml:lang="en">24581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24580" xml:lang="en">24580</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24573" xml:lang="en">24573</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24572" xml:lang="en">24572</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24557" xml:lang="en">24557</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24507" xml:lang="en">24507</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24465" xml:lang="en">24465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html" xml:lang="en">SUSE-SA:2007:023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=490" xml:lang="en">20070316 Multiple Vendor libwpd Multiple Buffer Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2805" xml:lang="en">FEDORA-2007-350</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11535" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11535" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file in which values to loop counters are not properly handled in the (1) WP3TablesGroup::_readContents and (2) WP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup functions.  NOTE: the integer overflow has been split into CVE-2007-1466.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:andrew_morgan:linux_pam:0.99.7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:andrew_morgan:linux_pam:0.99.7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0003</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:10.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-23T16:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/pam-list/2007-January/msg00017.html" xml:lang="en">[pam-list] 20070123 Linux-PAM 0.99.7.1 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0323" xml:lang="en">ADV-2007-0323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01277.html" xml:lang="en">[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01271.html" xml:lang="en">[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32017" xml:lang="en">32017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31739" xml:lang="en">linuxpam-pamunix-security-bypass(31739)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22204" xml:lang="en">22204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_3_sr.html" xml:lang="en">SUSE-SR:2007:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23858" xml:lang="en">23858</vuln:reference>
    </vuln:references>
    <vuln:summary>pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0004</vuln:cve-id>
    <vuln:published-datetime>2007-09-18T15:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:16:46.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-09-19T15:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=199715" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=199715</vuln:reference>
    </vuln:references>
    <vuln:summary>The NFS client implementation in the kernel in Red Hat Enterprise Linux (RHEL) 3, when a filesystem is mounted with the noacl option, checks permissions for the open system call via vfs_permission (mode bits) data rather than an NFS ACCESS call to the server, which allows local client processes to obtain a false success status from open calls that the server would deny, and possibly obtain sensitive information about file permissions on the server, as demonstrated in a root_squash environment.  NOTE: it is uncertain whether any scenarios involving this issue cross privilege boundaries.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.6"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.7"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.3"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21:rc1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.5"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21:rc2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:omnikey.aaitg:omnikey_cardman_4040"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:omnikey.aaitg:omnikey_cardman_4040</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0005</vuln:cve-id>
    <vuln:published-datetime>2007-03-09T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-03-12T10:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11238" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11238" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3" xml:lang="en">http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1035" xml:lang="en">https://issues.rpath.com/browse/RPL-1035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/32880" xml:lang="en">kernel-cardman4040drivers-bo(32880)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0872" xml:lang="en">ADV-2007-0872</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-489-1" xml:lang="en">USN-489-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-486-1" xml:lang="en">USN-486-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22870" xml:lang="en">22870</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/462300/100/0/threaded" xml:lang="en">20070309 Buffer Overflow in Linux Drivers for Omnikey CardMan 4040 (CVE-2007-0005)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/471457" xml:lang="en">20070615 rPSA-2007-0124-1 kernel xen</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0099.html" xml:lang="en">RHSA-2007:0099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33023" xml:lang="en">33023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" xml:lang="en">MDKSA-2007:078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1286" xml:lang="en">DSA-1286</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26139" xml:lang="en">26139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26133" xml:lang="en">26133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25691" xml:lang="en">25691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25078" xml:lang="en">25078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24901" xml:lang="en">24901</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24777" xml:lang="en">24777</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24518" xml:lang="en">24518</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24436" xml:lang="en">24436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2788" xml:lang="en">FEDORA-2007-336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2787" xml:lang="en">FEDORA-2007-335</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11238" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11238" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0006</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-09-15T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-06T17:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9829" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9829" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1097" xml:lang="en">https://issues.rpath.com/browse/RPL-1097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-451-1" xml:lang="en">USN-451-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22539" xml:lang="en">22539</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/471457" xml:lang="en">20070615 rPSA-2007-0124-1 kernel xen</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0099.html" xml:lang="en">RHSA-2007:0099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0085.html" xml:lang="en">RHSA-2007:0085</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_21_kernel.html" xml:lang="en">SUSE-SA:2007:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:060" xml:lang="en">MDKSA-2007:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:047" xml:lang="en">MDKSA-2007:047</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25691" xml:lang="en">25691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24752" xml:lang="en">24752</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24547" xml:lang="en">24547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24482" xml:lang="en">24482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24429" xml:lang="en">24429</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24300" xml:lang="en">24300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24259" xml:lang="en">24259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24109" xml:lang="en">24109</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.kernel.org/show_bug.cgi?id=7727" xml:lang="en">http://bugzilla.kernel.org/show_bug.cgi?id=7727</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9829" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9829" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnucash:gnucash:2.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnucash:gnucash:2.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0007</vuln:cve-id>
    <vuln:published-datetime>2007-02-19T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:11.297-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-20T14:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24225" xml:lang="en">24225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223233" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0653" xml:lang="en">ADV-2007-0653</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/32558" xml:lang="en">gnucash-symlink(32558)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22610" xml:lang="en">22610</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:046" xml:lang="en">MDKSA-2007:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=192&amp;release_id=487446" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=192&amp;release_id=487446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24317" xml:lang="en">24317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24226" xml:lang="en">24226</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2725" xml:lang="en">FEDORA-2007-256</vuln:reference>
    </vuln:references>
    <vuln:summary>gnucash 2.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) gnucash.trace, (2) qof.trace, and (3) qof.trace.[PID] temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.4.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.11.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.11.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.11.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.6.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9:rc</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0008</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-11T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-27T16:09:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10502" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10502" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/377812" xml:lang="en">VU#377812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-06.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-06.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=364319" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=364319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/32666" xml:lang="en">nss-mastersecret-bo(32666)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2141" xml:lang="en">ADV-2007-2141</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1165" xml:lang="en">ADV-2007-1165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0719" xml:lang="en">ADV-2007-0719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-431-1" xml:lang="en">USN-431-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017696" xml:lang="en">1017696</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22694" xml:lang="en">22694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32105" xml:lang="en">32105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" xml:lang="en">MDKSA-2007:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml" xml:lang="en">GLSA-200703-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1336" xml:lang="en">DSA-1336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1" xml:lang="en">102856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-18.xml" xml:lang="en">GLSA-200703-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24703" xml:lang="en">24703</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24650" xml:lang="en">24650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24562" xml:lang="en">24562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24522" xml:lang="en">24522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24410" xml:lang="en">24410</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24395" xml:lang="en">24395</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24389" xml:lang="en">24389</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24384" xml:lang="en">24384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24343" xml:lang="en">24343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24333" xml:lang="en">24333</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24328" xml:lang="en">24328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24320" xml:lang="en">24320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24293" xml:lang="en">24293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24290" xml:lang="en">24290</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24287" xml:lang="en">24287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24277" xml:lang="en">24277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24253" xml:lang="en">24253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24252" xml:lang="en">24252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24238" xml:lang="en">24238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24205" xml:lang="en">24205</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482" xml:lang="en">20070223 Mozilla Network Security Services SSLv2 Client Integer Underflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2728" xml:lang="en">FEDORA-2007-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2713" xml:lang="en">FEDORA-2007-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2711" xml:lang="en">FEDORA-2007-279</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2709" xml:lang="en">FEDORA-2007-278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1" xml:lang="en">102945</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" xml:lang="en">SSA:2007-066-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25597" xml:lang="en">25597</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25588" xml:lang="en">25588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24457" xml:lang="en">24457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24456" xml:lang="en">24456</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24455" xml:lang="en">24455</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24406" xml:lang="en">24406</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24342" xml:lang="en">24342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2749" xml:lang="en">FEDORA-2007-309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2747" xml:lang="en">FEDORA-2007-308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10502" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10502" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.11.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0009</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-27T16:16:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10174" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10174" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/592796" xml:lang="en">VU#592796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=364323" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=364323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/32663" xml:lang="en">nss-clientmasterkey-bo(32663)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2141" xml:lang="en">ADV-2007-2141</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1165" xml:lang="en">ADV-2007-1165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0719" xml:lang="en">ADV-2007-0719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-431-1" xml:lang="en">USN-431-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017696" xml:lang="en">1017696</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32106" xml:lang="en">32106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-06.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-06.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" xml:lang="en">MDKSA-2007:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml" xml:lang="en">GLSA-200703-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1336" xml:lang="en">DSA-1336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1" xml:lang="en">102945</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1" xml:lang="en">102856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" xml:lang="en">SSA:2007-066-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-18.xml" xml:lang="en">GLSA-200703-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24703" xml:lang="en">24703</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24650" xml:lang="en">24650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24562" xml:lang="en">24562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24522" xml:lang="en">24522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24410" xml:lang="en">24410</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24395" xml:lang="en">24395</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24389" xml:lang="en">24389</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24384" xml:lang="en">24384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24343" xml:lang="en">24343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24333" xml:lang="en">24333</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24293" xml:lang="en">24293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24290" xml:lang="en">24290</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24287" xml:lang="en">24287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24277" xml:lang="en">24277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24253" xml:lang="en">24253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483" xml:lang="en">20070223 Mozilla Network Security Services SSLv2 Server Stack Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2749" xml:lang="en">FEDORA-2007-309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2747" xml:lang="en">FEDORA-2007-308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2711" xml:lang="en">FEDORA-2007-279</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2709" xml:lang="en">FEDORA-2007-278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25597" xml:lang="en">25597</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25588" xml:lang="en">25588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24457" xml:lang="en">24457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24456" xml:lang="en">24456</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24455" xml:lang="en">24455</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24406" xml:lang="en">24406</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24342" xml:lang="en">24342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10174" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10174" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:the_gimp_team:gimp_toolkit:2.4.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:the_gimp_team:gimp_toolkit:2.4.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0010</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:11.737-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-24T15:03:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10325" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10325" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218932" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0331" xml:lang="en">ADV-2007-0331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0019.html" xml:lang="en">RHSA-2007:0019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31621" xml:lang="en">31621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-984" xml:lang="en">https://issues.rpath.com/browse/RPL-984</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-415-1" xml:lang="en">USN-415-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22209" xml:lang="en">22209</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_02_sr.html" xml:lang="en">SUSE-SR:2007:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:039" xml:lang="en">MDKSA-2007:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017552" xml:lang="en">1017552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24095" xml:lang="en">24095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24010" xml:lang="en">24010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24006" xml:lang="en">24006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23984" xml:lang="en">23984</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23935" xml:lang="en">23935</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23933" xml:lang="en">23933</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23884" xml:lang="en">23884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00011.html" xml:lang="en">DSA-1256</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10325" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10325" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:citrix:access_gateway:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:citrix:access_gateway:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:citrix:access_gateway:4.5::advanced"/>
        <cpe-lang:fact-ref name="cpe:/a:citrix:access_gateway:4.5::standard"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:citrix:access_gateway:4.5::standard</vuln:product>
      <vuln:product>cpe:/a:citrix:access_gateway:4.2</vuln:product>
      <vuln:product>cpe:/a:citrix:access_gateway:4.0</vuln:product>
      <vuln:product>cpe:/a:citrix:access_gateway:4.5::advanced</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0011</vuln:cve-id>
    <vuln:published-datetime>2007-11-05T12:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:12.110-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-11-06T19:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24975" xml:lang="en">24975</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26143" xml:lang="en">26143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/35510" xml:lang="en">citrix-access-unspeci-information-disclosure(35510)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2583" xml:lang="en">ADV-2007-2583</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/482626/100/100/threaded" xml:lang="en">20071022 Corsaire Security Advisory - Citrix Access Gateway session ID disclosure issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.citrix.com/article/CTX113814" xml:lang="en">http://support.citrix.com/article/CTX113814</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.citrix.com/article/CTX112803" xml:lang="en">http://support.citrix.com/article/CTX112803</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1018435" xml:lang="en">1018435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/45288" xml:lang="en">45288</vuln:reference>
    </vuln:references>
    <vuln:summary>The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the a referer log, browser history, or browser cache.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0012</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T18:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:16:47.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T10:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39549" xml:lang="en">sun-java-jpiexp32-dos(39549)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27185" xml:lang="en">27185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485942/100/0/threaded" xml:lang="en">20080108 Corsaire Security Advisory: Sun J2RE DoS issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3527" xml:lang="en">3527</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:chainkey_java_code_protection"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:chainkey_java_code_protection</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0014</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-17T11:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456734/100/0/threaded" xml:lang="en">20070112 Re: Corsaire Security Advisory: ChainKey Java Code Protection Bypass issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456712/100/0/threaded" xml:lang="en">20070112 Corsaire Security Advisory: ChainKey Java Code Protection Bypass issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33473" xml:lang="en">33473</vuln:reference>
    </vuln:references>
    <vuln:summary>ChainKey Java Code Protection allows attackers to decompile Java class files via a Java class loader with a modified defineClass method that saves the bytecode to a file before it is passed to the JVM.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0015</vuln:cve-id>
    <vuln:published-datetime>2007-01-01T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:12.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-02T01:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/442497" xml:lang="en">VU#442497</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-005A.html" xml:lang="en">TA07-005A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31203" xml:lang="en">quicktime-rtsp-url-bo(31203)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23540" xml:lang="en">23540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0001" xml:lang="en">ADV-2007-0001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21829" xml:lang="en">21829</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017461" xml:lang="en">1017461</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-01-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-01-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html" xml:lang="en">http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31023" xml:lang="en">31023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/blog/7/" xml:lang="en">http://secunia.com/blog/7/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3064" xml:lang="en">3064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Jan/msg00000.html" xml:lang="en">APPLE-SA-2007-01-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isc.sans.org/diary.html?storyid=2094" xml:lang="en">http://isc.sans.org/diary.html?storyid=2094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=304989" xml:lang="en">http://docs.info.apple.com/article.html?artnum=304989</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netfarer:movieplay:4.76"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netfarer:movieplay:4.76</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0016</vuln:cve-id>
    <vuln:published-datetime>2007-01-02T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-03T08:19:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21840" xml:lang="en">21840</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4051" xml:lang="en">4051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/22959" xml:lang="en">22959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32547" xml:lang="en">32547</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a LST file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.4a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.1</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.7.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.4</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.4a</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.5</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.7.1</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.7.2</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.6</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0017</vuln:cve-id>
    <vuln:published-datetime>2007-01-02T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-27T00:31:09.673-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-03T08:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14313" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14313" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.videolan.org/patches/vlc-0.8.6-MOAB-02-01-2007.patch" xml:lang="en">http://www.videolan.org/patches/vlc-0.8.6-MOAB-02-01-2007.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31226" xml:lang="en">vlcmediaplayer-udp-format-string(31226)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0026" xml:lang="en">ADV-2007-0026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.videolan.org/sa0701.html" xml:lang="en">http://www.videolan.org/sa0701.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.via.ecp.fr/via/ml/vlc-devel/2007-01/msg00005.html" xml:lang="en">[vlc-devel] 20070102 Security hole in VLC media player for Mac...</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21852" xml:lang="en">21852</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_13_xine.html" xml:lang="en">SUSE-SA:2007:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1252" xml:lang="en">DSA-1252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://trac.videolan.org/vlc/changeset/18481" xml:lang="en">http://trac.videolan.org/vlc/changeset/18481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017464" xml:lang="en">1017464</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-24.xml" xml:lang="en">GLSA-200701-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23971" xml:lang="en">23971</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23910" xml:lang="en">23910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23829" xml:lang="en">23829</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23592" xml:lang="en">23592</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-02-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-02-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31163" xml:lang="en">31163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_2.20070103045559.6753.timor.html" xml:lang="en">http://landonf.bikemonkey.org/code/macosx/MOAB_Day_2.20070103045559.6753.timor.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://applefun.blogspot.com/2007/01/moab-02-01-2007-vlc-media-player-udp.html" xml:lang="en">http://applefun.blogspot.com/2007/01/moab-02-01-2007-vlc-media-player-udp.html</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14313" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14313" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:altdo:convert_mp3_master:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:altdo:mp3_record_and_edit_audio_master:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:americanshareware:mp3_wav_converter:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:audio_edit_magic:audio_edit_magic:9.2.3_389"/>
        <cpe-lang:fact-ref name="cpe:/a:bearshare:bearshare:6.0.2.26789"/>
        <cpe-lang:fact-ref name="cpe:/a:cdburnerxp:cdburnerxp_pro:3.0.116"/>
        <cpe-lang:fact-ref name="cpe:/a:cheetahburner:cheetah_cd_burner:3.56"/>
        <cpe-lang:fact-ref name="cpe:/a:cheetahburner:cheetah_dvd_burner:1.79"/>
        <cpe-lang:fact-ref name="cpe:/a:code-it_softare:abasic_editor:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:code-it_softare:wave_mp3_editor:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dandans_digital_media_products:easy_audio_editor:7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:dandans_digital_media_products:full_audio_converter:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dandans_digital_media_products:music_editing_master:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dandans_digital_media_products:visual_video_converter:4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:digital_borneo:audio_mixer_and_editor:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_ringtone_maker:easy_ringtone_maker:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:expstudio:audio_editor:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:iaudiosoft.com:absolute_mp3_splitter:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:iaudiosoft.com:absolute_sound_recorder:3.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:iaudiosoft.com:absolute_video_to_audio_converter:2.7.9"/>
        <cpe-lang:fact-ref name="cpe:/a:imesh.com:imesh:7.0.2.26789"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_audio_concat:1.2.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_audio_editor:4.7.11"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_audio_tools:7.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_magic_music:5.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_movie_joiner:6.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_movie_joiner_and_splitter:6.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_movie_splitter:6.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_new_sound:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_video_converter:7.51.21"/>
        <cpe-lang:fact-ref name="cpe:/a:joshua_mediasoft:audio_convertor_plus:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:joshua_mediasoft:video_converter_plus:3.01"/>
        <cpe-lang:fact-ref name="cpe:/a:magicvideosoftare:magic_audio_converter:8.2.6_build_719"/>
        <cpe-lang:fact-ref name="cpe:/a:magicvideosoftare:magic_audio_recorder:5.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:magicvideosoftare:magic_music_editor:5.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mcfunsoft:audio_editor:6.3.3_build_489"/>
        <cpe-lang:fact-ref name="cpe:/a:mcfunsoft:audio_recorder_for_free:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcfunsoft:audio_studio:6.6.3_build_479"/>
        <cpe-lang:fact-ref name="cpe:/a:mcfunsoft:ipod_audio_studio:6.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mcfunsoft:ipod_music_converter:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcfunsoft:recording_to_ipod_solution:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediatox:aurora_media_workshop:3.3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:movavi:chiliburner:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:movavi:convertmovie:4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:movavi:dvd_to_ipod:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:movavi:splitmovie:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:movavi:suite:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:movavi:videomessage:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mp3-soft:mp3_normalizer:1.03"/>
        <cpe-lang:fact-ref name="cpe:/a:mystik_media_products:audioedit_deluxe:4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mystik_media_products:blaze_media_pro:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mystik_media_products:blaze_mediaconvert:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mystik_media_products:contextconvert_pro:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nctsoft_products:nctaudioeditor:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nctsoft_products:nctaudiofile2"/>
        <cpe-lang:fact-ref name="cpe:/a:nctsoft_products:nctaudiostudio:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nctsoft_products:nctdialogicvoice:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nextlevel_systems:audio_editor_gold:9.2.5_build_424"/>
        <cpe-lang:fact-ref name="cpe:/a:nextlevel_systems:audio_studio_gold:7.0.1.1_build_500"/>
        <cpe-lang:fact-ref name="cpe:/a:quikscribe:quikscribe_player:5.022.05"/>
        <cpe-lang:fact-ref name="cpe:/a:quikscribe:quikscribe_recorder:5.021.29"/>
        <cpe-lang:fact-ref name="cpe:/a:recordnrip:recordnrip:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rmbsoft:audioconvert:3.1.0.125"/>
        <cpe-lang:fact-ref name="cpe:/a:rmbsoft:soundedit_pro:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:roemer_software:easy_hi-q_converter:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:roemer_software:easy_hi-q_recorder:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:roemer_software:free_hi-q_recorder:1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sienzo:digital_music_mentor:2.6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:smart_media_systems:power_audio_editor:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:softdiv_softare:dexster:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:softdiv_softare:ivideomax:3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:softdiv_softare:mp3_to_wav_converter:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:softdiv_softare:snosh:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:softdiv_softare:videozilla:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:virtual_cd:virtual_cd:6.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:virtual_cd:virtual_cd:7.1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:virtual_cd:virtual_cd:8.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:virtual_cd:virtual_cd_file_server:7.1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xrlly_software:arial_audio_converter:2.3.40"/>
        <cpe-lang:fact-ref name="cpe:/a:xrlly_software:arial_sound_recorder:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xrlly_software:text_to_speech_maker:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:xwaver.com:magic_audio_editor_pro:10.3.1_build_476"/>
        <cpe-lang:fact-ref name="cpe:/a:xwaver.com:magic_music_studio_pro:7.0.2.1_build_500"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nextlevel_systems:audio_editor_gold:9.2.5_build_424</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_audio_editor:4.7.11</vuln:product>
      <vuln:product>cpe:/a:digital_borneo:audio_mixer_and_editor:1.1.0</vuln:product>
      <vuln:product>cpe:/a:mcfunsoft:ipod_music_converter:5.1</vuln:product>
      <vuln:product>cpe:/a:cheetahburner:cheetah_cd_burner:3.56</vuln:product>
      <vuln:product>cpe:/a:movavi:dvd_to_ipod:1.0</vuln:product>
      <vuln:product>cpe:/a:cdburnerxp:cdburnerxp_pro:3.0.116</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_movie_splitter:6.4.7</vuln:product>
      <vuln:product>cpe:/a:quikscribe:quikscribe_player:5.022.05</vuln:product>
      <vuln:product>cpe:/a:nextlevel_systems:audio_studio_gold:7.0.1.1_build_500</vuln:product>
      <vuln:product>cpe:/a:mcfunsoft:audio_recorder_for_free:6.1</vuln:product>
      <vuln:product>cpe:/a:nctsoft_products:nctaudiostudio:2.7.1</vuln:product>
      <vuln:product>cpe:/a:iaudiosoft.com:absolute_sound_recorder:3.4.5</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_video_converter:7.51.21</vuln:product>
      <vuln:product>cpe:/a:iaudiosoft.com:absolute_mp3_splitter:2.5.4</vuln:product>
      <vuln:product>cpe:/a:americanshareware:mp3_wav_converter:3.1.8</vuln:product>
      <vuln:product>cpe:/a:magicvideosoftare:magic_audio_converter:8.2.6_build_719</vuln:product>
      <vuln:product>cpe:/a:softdiv_softare:videozilla:2.5</vuln:product>
      <vuln:product>cpe:/a:mystik_media_products:blaze_mediaconvert:3.4</vuln:product>
      <vuln:product>cpe:/a:expstudio:audio_editor:4.0.2</vuln:product>
      <vuln:product>cpe:/a:mcfunsoft:ipod_audio_studio:6.2.4</vuln:product>
      <vuln:product>cpe:/a:softdiv_softare:snosh:1.4</vuln:product>
      <vuln:product>cpe:/a:code-it_softare:wave_mp3_editor:10.1</vuln:product>
      <vuln:product>cpe:/a:rmbsoft:audioconvert:3.1.0.125</vuln:product>
      <vuln:product>cpe:/a:movavi:chiliburner:2.3</vuln:product>
      <vuln:product>cpe:/a:nctsoft_products:nctaudioeditor:2.7.1</vuln:product>
      <vuln:product>cpe:/a:dandans_digital_media_products:full_audio_converter:4.2</vuln:product>
      <vuln:product>cpe:/a:xrlly_software:arial_sound_recorder:1.4.3</vuln:product>
      <vuln:product>cpe:/a:softdiv_softare:mp3_to_wav_converter:3.0</vuln:product>
      <vuln:product>cpe:/a:dandans_digital_media_products:easy_audio_editor:7.4</vuln:product>
      <vuln:product>cpe:/a:movavi:splitmovie:1.4</vuln:product>
      <vuln:product>cpe:/a:bearshare:bearshare:6.0.2.26789</vuln:product>
      <vuln:product>cpe:/a:joshua_mediasoft:video_converter_plus:3.01</vuln:product>
      <vuln:product>cpe:/a:dandans_digital_media_products:music_editing_master:5.2</vuln:product>
      <vuln:product>cpe:/a:recordnrip:recordnrip:1.0</vuln:product>
      <vuln:product>cpe:/a:mp3-soft:mp3_normalizer:1.03</vuln:product>
      <vuln:product>cpe:/a:virtual_cd:virtual_cd_file_server:7.1.0.3</vuln:product>
      <vuln:product>cpe:/a:sienzo:digital_music_mentor:2.6.0.3</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_movie_joiner:6.2.8</vuln:product>
      <vuln:product>cpe:/a:altdo:mp3_record_and_edit_audio_master:1.2</vuln:product>
      <vuln:product>cpe:/a:code-it_softare:abasic_editor:10.1</vuln:product>
      <vuln:product>cpe:/a:nctsoft_products:nctdialogicvoice:2.7.1</vuln:product>
      <vuln:product>cpe:/a:mystik_media_products:contextconvert_pro:3.1</vuln:product>
      <vuln:product>cpe:/a:mcfunsoft:audio_studio:6.6.3_build_479</vuln:product>
      <vuln:product>cpe:/a:imesh.com:imesh:7.0.2.26789</vuln:product>
      <vuln:product>cpe:/a:movavi:suite:3.5</vuln:product>
      <vuln:product>cpe:/a:mystik_media_products:audioedit_deluxe:4.10</vuln:product>
      <vuln:product>cpe:/a:mcfunsoft:recording_to_ipod_solution:5.1</vuln:product>
      <vuln:product>cpe:/a:magicvideosoftare:magic_audio_recorder:5.3.7</vuln:product>
      <vuln:product>cpe:/a:roemer_software:easy_hi-q_recorder:2.0</vuln:product>
      <vuln:product>cpe:/a:xrlly_software:arial_audio_converter:2.3.40</vuln:product>
      <vuln:product>cpe:/a:xwaver.com:magic_music_studio_pro:7.0.2.1_build_500</vuln:product>
      <vuln:product>cpe:/a:cheetahburner:cheetah_dvd_burner:1.79</vuln:product>
      <vuln:product>cpe:/a:virtual_cd:virtual_cd:8.0.0.6</vuln:product>
      <vuln:product>cpe:/a:xwaver.com:magic_audio_editor_pro:10.3.1_build_476</vuln:product>
      <vuln:product>cpe:/a:virtual_cd:virtual_cd:6.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mcfunsoft:audio_editor:6.3.3_build_489</vuln:product>
      <vuln:product>cpe:/a:roemer_software:free_hi-q_recorder:1.9</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_audio_tools:7.3.4</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_new_sound:5.1.1</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_audio_concat:1.2.0_beta</vuln:product>
      <vuln:product>cpe:/a:easy_ringtone_maker:easy_ringtone_maker:2.0.5</vuln:product>
      <vuln:product>cpe:/a:joshua_mediasoft:audio_convertor_plus:2.2</vuln:product>
      <vuln:product>cpe:/a:mystik_media_products:blaze_media_pro:7.0</vuln:product>
      <vuln:product>cpe:/a:mediatox:aurora_media_workshop:3.3.25</vuln:product>
      <vuln:product>cpe:/a:altdo:convert_mp3_master:1.1</vuln:product>
      <vuln:product>cpe:/a:xrlly_software:text_to_speech_maker:1.3.8</vuln:product>
      <vuln:product>cpe:/a:dandans_digital_media_products:visual_video_converter:4.4</vuln:product>
      <vuln:product>cpe:/a:magicvideosoftare:magic_music_editor:5.2.2</vuln:product>
      <vuln:product>cpe:/a:quikscribe:quikscribe_recorder:5.021.29</vuln:product>
      <vuln:product>cpe:/a:rmbsoft:soundedit_pro:2.1</vuln:product>
      <vuln:product>cpe:/a:movavi:videomessage:1.0</vuln:product>
      <vuln:product>cpe:/a:movavi:convertmovie:4.4</vuln:product>
      <vuln:product>cpe:/a:smart_media_systems:power_audio_editor:11.0.1</vuln:product>
      <vuln:product>cpe:/a:iaudiosoft.com:absolute_video_to_audio_converter:2.7.9</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_movie_joiner_and_splitter:6.2.8</vuln:product>
      <vuln:product>cpe:/a:softdiv_softare:ivideomax:3.9</vuln:product>
      <vuln:product>cpe:/a:softdiv_softare:dexster:3.0</vuln:product>
      <vuln:product>cpe:/a:audio_edit_magic:audio_edit_magic:9.2.3_389</vuln:product>
      <vuln:product>cpe:/a:virtual_cd:virtual_cd:7.1.0.2</vuln:product>
      <vuln:product>cpe:/a:roemer_software:easy_hi-q_converter:1.7</vuln:product>
      <vuln:product>cpe:/a:nctsoft_products:nctaudiofile2</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_magic_music:5.7.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0018</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-25T10:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/292713" xml:lang="en">VU#292713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0310" xml:lang="en">ADV-2007-0310</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-9/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-9/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-8/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-8/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-7/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-7/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-6/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-6/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-5/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-5/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-4/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-4/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-34/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-34/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-33/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-33/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-32/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-32/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-31/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-31/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-30/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-30/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-3/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-3/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-29/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-29/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-28/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-28/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-27/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-27/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-26/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-26/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-25/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-25/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-24/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-24/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-23/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-23/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-22/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-22/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-21/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-21/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-20/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-20/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-2/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-2/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-19/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-19/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-18/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-18/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-17/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-17/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-16/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-16/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-15/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-15/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-14/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-14/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-13/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-13/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-12/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-12/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-11/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-11/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-10/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-10/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/blog/6/" xml:lang="en">http://secunia.com/blog/6/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30459" xml:lang="en">30459</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30450" xml:lang="en">30450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30447" xml:lang="en">30447</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30446" xml:lang="en">30446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30439" xml:lang="en">30439</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30424" xml:lang="en">30424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30406" xml:lang="en">30406</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23568" xml:lang="en">23568</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23557" xml:lang="en">23557</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23553" xml:lang="en">23553</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23552" xml:lang="en">23552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23551" xml:lang="en">23551</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23543" xml:lang="en">23543</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23534" xml:lang="en">23534</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23532" xml:lang="en">23532</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23530" xml:lang="en">23530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23516" xml:lang="en">23516</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23511" xml:lang="en">23511</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23495" xml:lang="en">23495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23493" xml:lang="en">23493</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23485" xml:lang="en">23485</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23475" xml:lang="en">23475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31707" xml:lang="en">nctaudiofile2-multiple-bo(31707)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23892" xml:lang="en">23892</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22196" xml:lang="en">22196</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457965/100/200/threaded" xml:lang="en">20070124 Re: Secunia Research: NCTsoft Products NCTAudioFile2 ActiveXControl Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457940/100/200/threaded" xml:lang="en">20070124 Secunia Research: Sienzo Digital Music Mentor NCTAudioFile2ActiveX Control Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457936/100/200/threaded" xml:lang="en">20070124 Secunia Research: NCTsoft Products NCTAudioFile2 ActiveX ControlBuffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2007-50/advisory/" xml:lang="en">http://secunia.com/secunia_research/2007-50/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28407" xml:lang="en">28407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26101" xml:lang="en">26101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26100" xml:lang="en">26100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26046" xml:lang="en">26046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25993" xml:lang="en">25993</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23795" xml:lang="en">23795</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23753" xml:lang="en">23753</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23745" xml:lang="en">23745</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23565" xml:lang="en">23565</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23562" xml:lang="en">23562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23561" xml:lang="en">23561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23560" xml:lang="en">23560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23558" xml:lang="en">23558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23554" xml:lang="en">23554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23550" xml:lang="en">23550</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23548" xml:lang="en">23548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23546" xml:lang="en">23546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23544" xml:lang="en">23544</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23542" xml:lang="en">23542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23541" xml:lang="en">23541</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23536" xml:lang="en">23536</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23535" xml:lang="en">23535</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/22922" xml:lang="en">22922</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0019">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:maxum_development_corporation:rumpus_ftp_server:5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:maxum_development_corporation:rumpus_ftp_server:5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0019</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:13.297-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-21T22:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31594" xml:lang="en">rumpus-ftp-http-bo(31594)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-18-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-18-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32692" xml:lang="en">32692</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32689" xml:lang="en">32689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31594" xml:lang="en">rumpus-ftp-service-bo(31594)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23842" xml:lang="en">23842</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecified requests to the FTP service, and (2) allow remote attackers to execute arbitrary code via unspecified requests to the HTTP service.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:panic_transmit:panic_transmit:3.5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:panic_transmit:panic_transmit:3.5.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0020</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:13.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-23T21:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0273" xml:lang="en">ADV-2007-0273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22145" xml:lang="en">22145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23861" xml:lang="en">23861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-19-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-19-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32694" xml:lang="en">32694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31673" xml:lang="en">transmit-url-handler-bo(31673)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3160" xml:lang="en">3160</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:ichat:3.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:ichat:3.1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0021</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:13.657-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-22T20:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-047A.html" xml:lang="en">TA07-047A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/794752" xml:lang="en">VU#794752</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0274" xml:lang="en">ADV-2007-0274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-20-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-20-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32715" xml:lang="en">32715</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31679" xml:lang="en">ichat-aim-format-string(31679)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017661" xml:lang="en">1017661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22146" xml:lang="en">22146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24198" xml:lang="en">24198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" xml:lang="en">APPLE-SA-2007-02-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305102" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305102</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0022</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:13.783-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-22T20:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31677" xml:lang="en">macos-writeconfig-privilege-escalation(31677)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0074" xml:lang="en">ADV-2007-0074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017941" xml:lang="en">1017941</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22148" xml:lang="en">22148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31605" xml:lang="en">31605</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24966" xml:lang="en">24966</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23793" xml:lang="en">23793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-21-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-21-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:summary>Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to a malicious launchctl program.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0023</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:13.953-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-23T21:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-047A.html" xml:lang="en">TA07-047A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/315856" xml:lang="en">VU#315856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0074" xml:lang="en">ADV-2007-0074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-22-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-22-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31676" xml:lang="en">macos-inputmanager-privilege-escalation(31676)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22188" xml:lang="en">22188</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32695" xml:lang="en">32695</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017542" xml:lang="en">1017542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24198" xml:lang="en">24198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23846" xml:lang="en">23846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" xml:lang="en">APPLE-SA-2007-02-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305102" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305102</vuln:reference>
    </vuln:references>
    <vuln:summary>The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed when Cocoa applications attempt to notify the user.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:sp4"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::64-bit"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.01:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0024</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:14.080-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T00:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1058" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1058" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/122084" xml:lang="en">VU#122084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31287" xml:lang="en">ie-vml-record-bo(31287)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21930" xml:lang="en">21930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31250" xml:lang="en">31250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-004.mspx" xml:lang="en">MS07-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/?kbid=929969" xml:lang="en">929969</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017489" xml:lang="en">1017489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23677" xml:lang="en">23677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=462" xml:lang="en">20070109 Microsoft Windows VML Element Integer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0129" xml:lang="en">ADV-2007-0129</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0105" xml:lang="en">ADV-2007-0105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">SSRT071296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">SSRT071296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457164/100/0/threaded" xml:lang="en">20070117 Re: MS07-004 VML Integer Overflow Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457053/100/0/threaded" xml:lang="en">20070116 MS07-004 VML Integer Overflow Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-009.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-009.htm</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1058" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1058" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio_.net:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio_.net:2000:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio_.net:2003:gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:2000:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:xp_sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:xp_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_studio_.net:2003:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:2000:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_studio_.net:2000:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_studio_.net:2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:2003:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0025</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-06-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-13T20:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:157" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:157" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/932041" xml:lang="en">VU#932041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-012.mspx" xml:lang="en">MS07-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0581" xml:lang="en">ADV-2007-0581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017638" xml:lang="en">1017638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22476" xml:lang="en">22476</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31887" xml:lang="en">31887</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24150" xml:lang="en">24150</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:157" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:157" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0026</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:14.283-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-13T20:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:540" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:540" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/497756" xml:lang="en">VU#497756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-011.mspx" xml:lang="en">MS07-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0580" xml:lang="en">ADV-2007-0580</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017637" xml:lang="en">1017637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22483" xml:lang="en">22483</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31885" xml:lang="en">31885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24147" xml:lang="en">24147</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:540" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:540" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0027</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:14.393-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T07:23:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:119" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:119" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/749964" xml:lang="en">VU#749964</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21856" xml:lang="en">21856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" xml:lang="en">MS07-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017487" xml:lang="en">1017487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0103" xml:lang="en">ADV-2007-0103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31255" xml:lang="en">31255</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:119" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:119" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0028</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-03T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T07:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:768" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:768" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/493185" xml:lang="en">VU#493185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" xml:lang="en">MS07-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0103" xml:lang="en">ADV-2007-0103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21952" xml:lang="en">21952</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">SSRT071296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31249" xml:lang="en">31249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.fortinet.com/FortiGuardCenter/advisory/FGA-2007-01.html" xml:lang="en">http://www.fortinet.com/FortiGuardCenter/advisory/FGA-2007-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html" xml:lang="en">http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017485" xml:lang="en">1017485</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23676" xml:lang="en">23676</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:768" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:768" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability."  NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0029</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:14.627-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T07:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1102" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1102" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" xml:lang="en">MS07-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0103" xml:lang="en">ADV-2007-0103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21877" xml:lang="en">21877</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31256" xml:lang="en">31256</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017487" xml:lang="en">1017487</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1102" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1102" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka "Excel Malformed String Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0030</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:14.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T07:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:323" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:323" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/302836" xml:lang="en">VU#302836</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" xml:lang="en">MS07-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=460" xml:lang="en">20070109 Microsoft Excel Invalid Column Heap Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0103" xml:lang="en">ADV-2007-0103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21925" xml:lang="en">21925</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31257" xml:lang="en">31257</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017487" xml:lang="en">1017487</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:323" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:323" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0031</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:14.877-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T07:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:753" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:753" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/625532" xml:lang="en">VU#625532</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" xml:lang="en">MS07-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=461" xml:lang="en">20070109 Microsoft Excel Long Palette Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0103" xml:lang="en">ADV-2007-0103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21922" xml:lang="en">21922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">SSRT071296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31258" xml:lang="en">31258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017487" xml:lang="en">1017487</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:753" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:753" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0033</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:15.063-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T07:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:516" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:516" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/476900" xml:lang="en">VU#476900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-003.mspx" xml:lang="en">MS07-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0104" xml:lang="en">ADV-2007-0104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21931" xml:lang="en">21931</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31252" xml:lang="en">31252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017488" xml:lang="en">1017488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23674" xml:lang="en">23674</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:516" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:516" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0034</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-27T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T07:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:153" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:153" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/271860" xml:lang="en">VU#271860</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-003.mspx" xml:lang="en">MS07-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0104" xml:lang="en">ADV-2007-0104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21936" xml:lang="en">21936</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456589/100/0/threaded" xml:lang="en">20070111 Computer Terrorism (UK) :: Incident Response Centre - Microsoft Outlook Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31254" xml:lang="en">31254</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.computerterrorism.com/research/ct09-01-2007.htm" xml:lang="en">http://www.computerterrorism.com/research/ct09-01-2007.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017488" xml:lang="en">1017488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23674" xml:lang="en">23674</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:153" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:153" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2006"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2006</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0035</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-05-09T08:55:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1737" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1737" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/260777" xml:lang="en">VU#260777</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx" xml:lang="en">MS07-024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1709" xml:lang="en">ADV-2007-1709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018013" xml:lang="en">1018013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23804" xml:lang="en">23804</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" xml:lang="en">SSRT071422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/34387" xml:lang="en">34387</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1737" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1737" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the "Word Array Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:professional_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::gold:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0038</vuln:cve-id>
    <vuln:published-datetime>2007-03-30T16:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-11-05T22:30:06.843-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-03-31T18:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1854" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1854" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-100A.html" xml:lang="en">TA07-100A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-093A.html" xml:lang="en">TA07-093A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-089A.html" xml:lang="en">TA07-089A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/191609" xml:lang="en">VU#191609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/33301" xml:lang="en">windows-ani-code-execution(33301)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/33301" xml:lang="en">windows-ani-code-execution(33301)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1215" xml:lang="en">ADV-2007-1215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" xml:lang="en">SSRT071354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" xml:lang="en">SSRT071354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/464460/100/100/threaded" xml:lang="en">20070402 MS announces out-of-band patch for ANI 0day</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/464459/100/100/threaded" xml:lang="en">20070402 More information on ZERT patch for ANI 0day</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/464342/100/0/threaded" xml:lang="en">20070331 RE: [Full-disclosure] 0-day ANI vulnerability in Microsoft Windows(CVE-2007-0038)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/464340/100/0/threaded" xml:lang="en">20070331 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/464339/100/0/threaded" xml:lang="en">20070330 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/464269/100/0/threaded" xml:lang="en">20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33629" xml:lang="en">33629</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx" xml:lang="en">MS07-017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp" xml:lang="en">http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2542" xml:lang="en">2542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24659" xml:lang="en">24659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3634" xml:lang="en">3634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0470.html" xml:lang="en">20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1854" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1854" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2007"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0039</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-05-09T11:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1593" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1593" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx" xml:lang="en">MS07-026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/33888" xml:lang="en">exchange-ical-dos(33888)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1711" xml:lang="en">ADV-2007-1711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018015" xml:lang="en">1018015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23808" xml:lang="en">23808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/468047/100/0/threaded" xml:lang="en">20070508 Exchange Calendar MODPROPS Denial of Service (CVE-2007-0039)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/34390" xml:lang="en">34390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.determina.com/security.research/vulnerabilities/exchange-ical-modprops.html" xml:lang="en">http://www.determina.com/security.research/vulnerabilities/exchange-ical-modprops.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25183" xml:lang="en">25183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063232.html" xml:lang="en">20070509 Exchange Calendar MODPROPS Denial of Service (CVE-2007-0039)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1593" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1593" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp1:itanium</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0040</vuln:cve-id>
    <vuln:published-datetime>2007-07-10T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:26:47.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-07-12T20:38:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2012" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2012" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" xml:lang="en">TA07-191A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/487905" xml:lang="en">VU#487905</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/ms07-039.mspx" xml:lang="en">MS07-039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2481" xml:lang="en">ADV-2007-2481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35960" xml:lang="en">35960</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018355" xml:lang="en">1018355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24800" xml:lang="en">24800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/267.html" xml:lang="en">20070710 Microsoft Windows Active Directory Remote Code Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26002" xml:lang="en">26002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" xml:lang="en">SSRT071446</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2012" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2012" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0041">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:2000"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:2003"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:xp"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0041</vuln:cve-id>
    <vuln:published-datetime>2007-07-10T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:26:48.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-07-13T23:06:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2093" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2093" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" xml:lang="en">TA07-191A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx" xml:lang="en">MS07-040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/34637" xml:lang="en">ms-dotnet-pe-loader-bo(34637)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2482" xml:lang="en">ADV-2007-2482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018356" xml:lang="en">1018356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24778" xml:lang="en">24778</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26003" xml:lang="en">26003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35954" xml:lang="en">35954</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" xml:lang="en">SSRT071446</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2093" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2093" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:2000"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:2003"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:xp"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0042</vuln:cve-id>
    <vuln:published-datetime>2007-07-10T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:15.970-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-07-13T11:58:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2070" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2070" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" xml:lang="en">TA07-191A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2482" xml:lang="en">ADV-2007-2482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018356" xml:lang="en">1018356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx" xml:lang="en">MS07-040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security-assessment.com/files/advisories/2007-07-11_Multiple_.NET_Null_Byte_Injection_Vulnerabilities.pdf" xml:lang="en">http://security-assessment.com/files/advisories/2007-07-11_Multiple_.NET_Null_Byte_Injection_Vulnerabilities.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26003" xml:lang="en">26003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" xml:lang="en">SSRT071446</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2070" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2070" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:2000"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:2003"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:xp"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0043</vuln:cve-id>
    <vuln:published-datetime>2007-07-10T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:26:48.343-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-07-13T12:03:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1873" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1873" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" xml:lang="en">TA07-191A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx" xml:lang="en">MS07-040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/34639" xml:lang="en">ms-dotnet-jit-bo(34639)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2482" xml:lang="en">ADV-2007-2482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018356" xml:lang="en">1018356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24811" xml:lang="en">24811</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26003" xml:lang="en">26003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35956" xml:lang="en">35956</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" xml:lang="en">SSRT071446</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1873" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1873" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".</vuln:summary>
  </entry>
  <entry id="CVE-2007-0044">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.1::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.1::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.2::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.2::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.3::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.3::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.4::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.4::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.5::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.5::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.6::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.6::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.7::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.7::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_3d"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::elements"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.1::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::elements</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.2::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.7::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.7::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.4::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.6::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.4::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.6::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.5::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_3d</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.1::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.5::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.3::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.3::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.2::standard</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0044</vuln:cve-id>
    <vuln:published-datetime>2007-01-03T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:16.203-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-03T17:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10042" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10042" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.wisec.it/vulns.php?page=9" xml:lang="en">http://www.wisec.it/vulns.php?page=9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31266" xml:lang="en">adobe-acrobat-pdf-csrf(31266)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0032" xml:lang="en">ADV-2007-0032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21858" xml:lang="en">21858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded" xml:lang="en">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0144.html" xml:lang="en">RHSA-2008:0144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017469" xml:lang="en">1017469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2090" xml:lang="en">2090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-16.xml" xml:lang="en">GLSA-200701-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29065" xml:lang="en">29065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23882" xml:lang="en">23882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23812" xml:lang="en">23812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" xml:lang="en">SUSE-SA:2007:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" xml:lang="en">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10042" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10042" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.1::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.1::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.2::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.2::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.3::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.3::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.4::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.4::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.5::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.5::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.6::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.6::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.7::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.7::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_3d"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::elements"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.1::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::elements</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.2::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.7::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.7::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.4::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.6::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.4::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.6::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.5::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_3d</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.1::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.5::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.3::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.3::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.2::standard</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0045</vuln:cve-id>
    <vuln:published-datetime>2007-01-03T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-13T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-03T17:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9693" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9693" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6487" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6487" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-286B.html" xml:lang="en">TA09-286B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/815960" xml:lang="en">VU#815960</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.wisec.it/vulns.php?page=9" xml:lang="en">http://www.wisec.it/vulns.php?page=9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2007-0017.html" xml:lang="en">RHSA-2007:0017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31271" xml:lang="en">adobe-acrobat-pdf-xss(31271)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/2898" xml:lang="en">ADV-2009-2898</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0957" xml:lang="en">ADV-2007-0957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0032" xml:lang="en">ADV-2007-0032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21858" xml:lang="en">21858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455906/100/0/threaded" xml:lang="en">20070104 Universal PDF XSS After Party</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded" xml:lang="en">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455836/100/0/threaded" xml:lang="en">20070103 RE: [WEB SECURITY] Universal XSS with PDF files: highly dangerous</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455831/100/0/threaded" xml:lang="en">20070103 Re: [WEB SECURITY] Universal XSS with PDF files: highly dangerous</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455800/100/0/threaded" xml:lang="en">20070103 Re: Universal XSS with PDF files: highly dangerous</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455790/100/0/threaded" xml:lang="en">20070103 Universal XSS with PDF files: highly dangerous</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0021.html" xml:lang="en">RHSA-2007:0021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-02.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-02.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gnucitizen.org/blog/universal-pdf-xss-after-party" xml:lang="en">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.gnucitizen.org/blog/danger-danger-danger/" xml:lang="en">http://www.gnucitizen.org/blog/danger-danger-danger/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.disenchant.ch/blog/hacking-with-browser-plugins/34" xml:lang="en">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb09-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb09-15.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb07-01.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb07-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/advisories/apsa07-02.html" xml:lang="en">http://www.adobe.com/support/security/advisories/apsa07-02.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/advisories/apsa07-01.html" xml:lang="en">http://www.adobe.com/support/security/advisories/apsa07-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1" xml:lang="en">102847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1023007" xml:lang="en">1023007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017469" xml:lang="en">1017469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2090" xml:lang="en">2090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-16.xml" xml:lang="en">GLSA-200701-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33754" xml:lang="en">33754</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24533" xml:lang="en">24533</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24457" xml:lang="en">24457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23882" xml:lang="en">23882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23877" xml:lang="en">23877</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23812" xml:lang="en">23812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23691" xml:lang="en">23691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23483" xml:lang="en">23483</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" xml:lang="en">SUSE-SA:2007:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html" xml:lang="en">http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9693" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9693" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6487" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6487" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0046</vuln:cve-id>
    <vuln:published-datetime>2007-01-03T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:16.610-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-03T17:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9684" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9684" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.wisec.it/vulns.php?page=9" xml:lang="en">http://www.wisec.it/vulns.php?page=9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0957" xml:lang="en">ADV-2007-0957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0032" xml:lang="en">ADV-2007-0032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded" xml:lang="en">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" xml:lang="en">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2007-0017.html" xml:lang="en">RHSA-2007:0017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31272" xml:lang="en">adobe-acrobat-msvcrt-code-execution(31272)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0021.html" xml:lang="en">RHSA-2007:0021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb07-01.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb07-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1" xml:lang="en">102847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017469" xml:lang="en">1017469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2090" xml:lang="en">2090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-16.xml" xml:lang="en">GLSA-200701-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24533" xml:lang="en">24533</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23882" xml:lang="en">23882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23877" xml:lang="en">23877</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23812" xml:lang="en">23812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23691" xml:lang="en">23691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" xml:lang="en">SUSE-SA:2007:011</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9684" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9684" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0047</vuln:cve-id>
    <vuln:published-datetime>2007-01-03T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:16.737-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-03T17:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31291" xml:lang="en">adobe-acrobat-xmlhttp-response-splitting(31291)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0032" xml:lang="en">ADV-2007-0032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017469" xml:lang="en">1017469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23882" xml:lang="en">23882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" xml:lang="en">SUSE-SA:2007:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" xml:lang="en">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</vuln:reference>
    </vuln:references>
    <vuln:summary>CRLF injection vulnerability in Adobe Acrobat Reader Plugin before 8.0.0, when used with the Microsoft.XMLHTTP ActiveX object in Internet Explorer, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the javascript: URI in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.1::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.1::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.2::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.2::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.3::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.3::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.4::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.4::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.5::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.5::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.6::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.6::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.7::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.7::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_3d"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::elements"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.1::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::elements</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.2::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.7::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.7::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.4::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.6::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.4::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.6::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.5::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_3d</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.1::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.5::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.3::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.3::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.2::standard</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0048</vuln:cve-id>
    <vuln:published-datetime>2007-01-03T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:16.830-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-03T17:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6348" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6348" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-286B.html" xml:lang="en">TA09-286B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.wisec.it/vulns.php?page=9" xml:lang="en">http://www.wisec.it/vulns.php?page=9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31273" xml:lang="en">adobe-acrobat-character-dos(31273)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/2898" xml:lang="en">ADV-2009-2898</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0032" xml:lang="en">ADV-2007-0032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded" xml:lang="en">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb09-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb09-15.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb07-01.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb07-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1023007" xml:lang="en">1023007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017469" xml:lang="en">1017469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-16.xml" xml:lang="en">GLSA-200701-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33754" xml:lang="en">33754</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23882" xml:lang="en">23882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23812" xml:lang="en">23812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31596" xml:lang="en">31596</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" xml:lang="en">SUSE-SA:2007:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html" xml:lang="en">http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" xml:lang="en">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2090" xml:lang="en">2090</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6348" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6348" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to a "cross-site scripting issue."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:geckovich:tasktracker:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:geckovich:tasktracker_pro:1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:geckovich:tasktracker_pro:1.5</vuln:product>
      <vuln:product>cpe:/a:geckovich:tasktracker:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0049</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:27.267-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-04T09:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31235" xml:lang="en">tasktrackerpro-customize-auth-bypass(31235)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21847" xml:lang="en">21847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23564" xml:lang="en">23564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31682" xml:lang="en">31682</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3068" xml:lang="en">3068</vuln:reference>
    </vuln:references>
    <vuln:summary>Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add action with a modified GroupID in a direct request to Customize.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openpinboard:openpinboard:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openpinboard:openpinboard:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0050</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:27.437-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-04T10:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455795/100/0/threaded" xml:lang="en">20070103 OpenPinboard &lt;= Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455818/100/0/threaded" xml:lang="en">20070103 Re: OpenPinboard &lt;= Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33375" xml:lang="en">33375</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2007-01/0176.html" xml:lang="en">20070106 Re: OpenPinboard &lt;= Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  PHP remote file inclusion vulnerability in index.php in OpenPinboard 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the language parameter.  NOTE: this issue has been disputed by the developer and a third party, since the variable is set before use. CVE analysis suggests that there is a small time window of risk before the installation is complete.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:iphoto:6.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:iphoto:6.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0051</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-04T13:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31281" xml:lang="en">iphoto-xmltitle-format-string(31281)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0057" xml:lang="en">ADV-2007-0057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21871" xml:lang="en">21871</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455968/100/0/threaded" xml:lang="en">20070104 DMA[2007-0104a] - 'iLife iPhoto Photocasing Format String Vulnerability'</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalmunition.com/DMA%5B2007-0104a%5D.txt" xml:lang="en">http://www.digitalmunition.com/DMA[2007-0104a].txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23615" xml:lang="en">23615</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-04-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-04-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31165" xml:lang="en">31165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3080" xml:lang="en">3080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar//msg00003.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305215" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0100.html" xml:lang="en">20070104 DMA[2007-0104a] - 'iLife iPhoto Photocasing Format String Vulnerability'</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0052">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:vizayn_haber:vizayn_haber"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vizayn_haber:vizayn_haber</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0052</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:17.237-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-04T18:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0015" xml:lang="en">ADV-2007-0015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21836" xml:lang="en">21836</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23576" xml:lang="en">23576</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31518" xml:lang="en">31518</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3061" xml:lang="en">3061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31213" xml:lang="en">vicayn-haberdetay-sql-injection(31213)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in haberdetay.asp in Vizayn Haber allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:asp_siteware:autodealer:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:asp_siteware:autodealer:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0053</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:17.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-04T18:18:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0016" xml:lang="en">ADV-2007-0016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21833" xml:lang="en">21833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23572" xml:lang="en">23572</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32539" xml:lang="en">32539</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3062" xml:lang="en">3062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31219" xml:lang="en">autodealer-detail-sql-injection(31219)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the iPro parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:belchior_foundry:vcard_pro"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:belchior_foundry:vcard_pro</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0054</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:28.203-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-04T18:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21844" xml:lang="en">21844</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455615/100/0/threaded" xml:lang="en">20070101 vBulletin vCard PRO XSS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33359" xml:lang="en">33359</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31182" xml:lang="en">vcard-gbrowse-xss(31182)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior Foundry vCard PRO allows remote attackers to inject arbitrary web script or HTML via the sortby parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fersch:formbankserver:1.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fersch:formbankserver:1.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0055</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:17.533-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-04T18:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0012" xml:lang="en">ADV-2007-0012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23539" xml:lang="en">23539</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32545" xml:lang="en">32545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31214" xml:lang="en">formbankserver-name-directory-traversal(31214)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3063" xml:lang="en">3063</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in formbankcgi.exe/AbfrageForm in Formbankserver 1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the Name parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ashopsoftware:ashop_administration_panel"/>
        <cpe-lang:fact-ref name="cpe:/a:ashopsoftware:ashop_deluxe:4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ashopsoftware:ashop_deluxe:4.5</vuln:product>
      <vuln:product>cpe:/a:ashopsoftware:ashop_administration_panel</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0056</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:17.643-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-04T18:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0028" xml:lang="en">ADV-2007-0028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21845" xml:lang="en">21845</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455629/100/0/threaded" xml:lang="en">20070101 AShop Shopping Cart Multiple XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32558" xml:lang="en">32558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32557" xml:lang="en">32557</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32556" xml:lang="en">32556</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32555" xml:lang="en">32555</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32554" xml:lang="en">32554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32553" xml:lang="en">32553</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31178" xml:lang="en">ashop-multiple-scripts-xss(31178)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2091" xml:lang="en">2091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23547" xml:lang="en">23547</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:clean_access:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:clean_access:3.6.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:clean_access:4.0.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:clean_access:3.5.9</vuln:product>
      <vuln:product>cpe:/o:cisco:clean_access:3.6.1.1</vuln:product>
      <vuln:product>cpe:/o:cisco:clean_access:4.0.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0057</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:17.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-04T18:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml" xml:lang="en">20070103 Multiple Vulnerabilities in Cisco Clean Access</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0030" xml:lang="en">ADV-2007-0030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32578" xml:lang="en">32578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017465" xml:lang="en">1017465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23617" xml:lang="en">23617</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:clean_access:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:clean_access:3.6.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:clean_access:3.5.9</vuln:product>
      <vuln:product>cpe:/o:cisco:clean_access:3.6.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0058</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:17.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-04T18:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0030" xml:lang="en">ADV-2007-0030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml" xml:lang="en">20070103 Multiple Vulnerabilities in Cisco Clean Access</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017465" xml:lang="en">1017465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23556" xml:lang="en">23556</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32579" xml:lang="en">32579</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0059</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:29.483-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T10:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/304064" xml:lang="en">VU#304064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/" xml:lang="en">http://www.gnucitizen.org/blog/backdooring-quicktime-movies/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-03-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-03-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31164" xml:lang="en">31164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" xml:lang="en">APPLE-SA-2007-03-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305149" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305149</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0060">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ca:advantage_data_transport:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_portal:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_san_manager:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_san_manager:11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:cleverpath_aion:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:cleverpath_ecm:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:cleverpath_olap:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:cleverpath_predictive_analysis_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:cleverpath_predictive_analysis_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_application_performance_monitor:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_application_performance_monitor:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_asset_management:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_asset_management:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_asset_management:3.2:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_asset_management:3.2:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_asset_management:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_asset_management:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_data_transport_option:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_enterprise_job_manager:1.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_enterprise_job_manager:1.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_jasmine:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_management:4.0::lotus_notes_domino"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_management:4.0::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_management:4.1::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_management:5.0.1::web_servers"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_management:5.0::web_servers"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_network_and_systems_management:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_network_and_systems_management:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_nsm_wireless_network_management_option:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_remote_control:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_remote_control:6.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_service_level_management:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_service_level_management:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_service_level_management:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_service_level_management:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_software_delivery:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_software_delivery:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_software_delivery:3.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_software_delivery:3.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_software_delivery:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_software_delivery:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_tng:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_tng:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_tng:2.2:::jp"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_tng:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_tng:2.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:brightstor_san_manager:11.5</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_service_level_management:3.0.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_management:4.0::lotus_notes_domino</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_network_and_systems_management:3.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_application_performance_monitor:3.5</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_tng:2.2:::jp</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_tng:2.2</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:2.7</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_enterprise_job_manager:1.0:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_asset_management:3.2:sp2</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_asset_management:3.2:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_software_delivery:3.1:sp2</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_management:4.1::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_data_transport_option:2.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_network_and_systems_management:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_software_delivery:3.1:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_management:4.0::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_management:5.0::web_servers</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_nsm_wireless_network_management_option:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_asset_management:3.1</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:2.9</vuln:product>
      <vuln:product>cpe:/a:ca:cleverpath_ecm:3.5</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_application_performance_monitor:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_portal:11.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_asset_management:4.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_asset_management:4.0:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_software_delivery:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_tng:2.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_tng:2.4</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_enterprise_job_manager:1.0:sp2</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:2.1</vuln:product>
      <vuln:product>cpe:/a:ca:cleverpath_aion:10.0</vuln:product>
      <vuln:product>cpe:/a:ca:cleverpath_predictive_analysis_server:2.0</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:8.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_software_delivery:4.0:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_service_level_management:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:advantage_data_transport:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_remote_control:6.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_management:5.0.1::web_servers</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:2.4</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_jasmine:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_service_level_management:3.0.2</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_software_delivery:4.0</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_san_manager:11.1</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:8.1</vuln:product>
      <vuln:product>cpe:/a:ca:cleverpath_olap:5.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_service_level_management:3.5</vuln:product>
      <vuln:product>cpe:/a:ca:cleverpath_predictive_analysis_server:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_software_delivery:3.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_tng:2.4.2</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_remote_control:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_asset_management:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0060</vuln:cve-id>
    <vuln:published-datetime>2007-07-25T20:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:18.080-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-07-26T13:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/32234" xml:lang="en">systems-management-bo(32234)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2638" xml:lang="en">ADV-2007-2638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25051" xml:lang="en">25051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/272.html" xml:lang="en">20070724 CA Message Queuing Server (Cam.exe) Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.asp" xml:lang="en">http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26190" xml:lang="en">26190</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018449" xml:lang="en">1018449</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/474602/100/0/threaded" xml:lang="en">20070725 [CAID 35527]: CA Message Queuing (CAM / CAFT) Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809" xml:lang="en">http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0061">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:1.0.3_build_54075"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:2.0.1_build_55017"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.5_build_56455"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:2.0.1_build_55017"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0.4_build_56528"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_34685"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.5_build_56455"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:6.0.1_build_55017"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:player:2.0.1_build_55017</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.1</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_34685</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.5_build_56455</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:6.0.1_build_55017</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.5_build_56455</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0.4_build_56528</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:1.0</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:6.0</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:1.0.3_build_54075</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:2.0.1_build_55017</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0061</vuln:cve-id>
    <vuln:published-datetime>2007-09-21T15:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:18.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-09-24T10:49:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/33101" xml:lang="en">dhcp-malformed-packet-bo(33101)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" xml:lang="en">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html" xml:lang="en">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/server/doc/releasenotes_server.html" xml:lang="en">http://www.vmware.com/support/server/doc/releasenotes_server.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/player2/doc/releasenotes_player2.html" xml:lang="en">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/player/doc/releasenotes_player.html" xml:lang="en">http://www.vmware.com/support/player/doc/releasenotes_player.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html" xml:lang="en">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ace/doc/releasenotes_ace.html" xml:lang="en">http://www.vmware.com/support/ace/doc/releasenotes_ace.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3229" xml:lang="en">ADV-2007-3229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25729" xml:lang="en">25729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/275.html" xml:lang="en">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-543-1" xml:lang="en">USN-543-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018717" xml:lang="en">1018717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200711-23.xml" xml:lang="en">GLSA-200711-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/27706" xml:lang="en">27706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/27694" xml:lang="en">27694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26890" xml:lang="en">26890</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" xml:lang="en">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</vuln:reference>
    </vuln:references>
    <vuln:summary>The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that triggers "corrupt stack memory."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0062">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:4.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.0_build_13124"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.1_build_19175"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_34685"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_42958"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.4_build_44386"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:workstation:5.5.1</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:1.0.3</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:3.4</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:4.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_34685</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.4_build_44386</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.4</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:2.0</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0.3</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.0_build_13124</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:4.0.2</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_42958</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:6.0</vuln:product>
      <vuln:product>cpe:/a:vmware:player:2.0</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.1_build_19175</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.4</vuln:product>
      <vuln:product>cpe:/a:vmware:vmware_workstation:6.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:4.0</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:4.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0062</vuln:cve-id>
    <vuln:published-datetime>2007-09-21T15:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-09-24T11:12:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/33102" xml:lang="en">dhcp-param-overflow(33102)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" xml:lang="en">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html" xml:lang="en">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/server/doc/releasenotes_server.html" xml:lang="en">http://www.vmware.com/support/server/doc/releasenotes_server.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/player2/doc/releasenotes_player2.html" xml:lang="en">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/player/doc/releasenotes_player.html" xml:lang="en">http://www.vmware.com/support/player/doc/releasenotes_player.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html" xml:lang="en">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ace/doc/releasenotes_ace.html" xml:lang="en">http://www.vmware.com/support/ace/doc/releasenotes_ace.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25729" xml:lang="en">25729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/275.html" xml:lang="en">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=339561" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=339561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3229" xml:lang="en">ADV-2007-3229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-543-1" xml:lang="en">USN-543-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018717" xml:lang="en">1018717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/501759/100/0/threaded" xml:lang="en">20090312 rPSA-2009-0041-1 dhclient dhcp libdhcp4client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:153" xml:lang="en">MDVSA-2009:153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2009-0041" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2009-0041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200808-05.xml" xml:lang="en">GLSA-200808-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200711-23.xml" xml:lang="en">GLSA-200711-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34263" xml:lang="en">34263</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31396" xml:lang="en">31396</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/27706" xml:lang="en">27706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/27694" xml:lang="en">27694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26890" xml:lang="en">26890</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" xml:lang="en">SUSE-SR:2009:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" xml:lang="en">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=227135" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=227135</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:esx_server:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:esx_server:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:esx_server:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:esx_server:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:esx_server:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:esx_server:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:1.0.3_build_54075"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:2.0.1_build_55017"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.5_build_56455"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:2.0.1_build_55017"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0.4_build_56528"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_34685"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.5_build_56455"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:6.0.1_build_55017"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:player:2.0.1_build_55017</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.1</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_34685</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.5_build_56455</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:6.0.1_build_55017</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.5_build_56455</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5</vuln:product>
      <vuln:product>cpe:/a:vmware:esx_server:2.5.3</vuln:product>
      <vuln:product>cpe:/a:vmware:esx_server:2.0.2</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0.4_build_56528</vuln:product>
      <vuln:product>cpe:/a:vmware:esx_server:3.0.0</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:1.0</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:6.0</vuln:product>
      <vuln:product>cpe:/a:vmware:esx_server:2.1.3</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:1.0.3_build_54075</vuln:product>
      <vuln:product>cpe:/a:vmware:esx_server:2.5.4</vuln:product>
      <vuln:product>cpe:/a:vmware:esx_server:3.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:2.0.1_build_55017</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0063</vuln:cve-id>
    <vuln:published-datetime>2007-09-21T15:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:18.393-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-09-24T11:01:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/33103" xml:lang="en">dhcp-param-underflow(33103)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" xml:lang="en">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html" xml:lang="en">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/server/doc/releasenotes_server.html" xml:lang="en">http://www.vmware.com/support/server/doc/releasenotes_server.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/player2/doc/releasenotes_player2.html" xml:lang="en">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/player/doc/releasenotes_player.html" xml:lang="en">http://www.vmware.com/support/player/doc/releasenotes_player.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html" xml:lang="en">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ace/doc/releasenotes_ace.html" xml:lang="en">http://www.vmware.com/support/ace/doc/releasenotes_ace.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25729" xml:lang="en">25729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/275.html" xml:lang="en">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3229" xml:lang="en">ADV-2007-3229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-543-1" xml:lang="en">USN-543-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018717" xml:lang="en">1018717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200711-23.xml" xml:lang="en">GLSA-200711-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/27706" xml:lang="en">27706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/27694" xml:lang="en">27694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26890" xml:lang="en">26890</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" xml:lang="en">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_format_runtime:7.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_format_runtime:9"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_format_runtime:9.5"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_format_runtime:9.5::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_format_runtime:11"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_services:9.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_media_format_runtime:11</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_services:9.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_format_runtime:9.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_format_runtime:7.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_format_runtime:9</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_format_runtime:9.5::x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0064</vuln:cve-id>
    <vuln:published-datetime>2007-12-11T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-15T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-12-11T19:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:3622" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3622" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-345A.html" xml:lang="en">TA07-345A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/319385" xml:lang="en">VU#319385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms07-068.mspx" xml:lang="en">MS07-068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/4183" xml:lang="en">ADV-2007-4183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019074" xml:lang="en">1019074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/26776" xml:lang="en">26776</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485268/100/0/threaded" xml:lang="en">SSRT071506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485268/100/0/threaded" xml:lang="en">SSRT071506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28034" xml:lang="en">28034</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:3622" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:3622" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office:::mac%2Bos"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_basic:6.0:sp6"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:visual_basic:6.0:sp6</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:::mac%2Bos</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0065</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:18.610-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T18:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5388" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5388" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-008.mspx" xml:lang="en">MS08-008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0510/references" xml:lang="en">ADV-2008-0510</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019373" xml:lang="en">1019373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27661" xml:lang="en">27661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28902" xml:lang="en">28902</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5388" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5388" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:standard"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::gold:itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:small_business_server:2003::sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:home_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:home_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:small_business_server:2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:standard</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::gold:itanium</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0066</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T15:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-28T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T11:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5271" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5271" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-008A.html" xml:lang="en">TA08-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-001.mspx" xml:lang="en">MS08-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28297" xml:lang="en">28297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39254" xml:lang="en">win-tcpip-icmp-dos(39254)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0069" xml:lang="en">ADV-2008-0069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27139" xml:lang="en">27139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded" xml:lang="en">SSRT080003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded" xml:lang="en">HPSBST02304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/282.html" xml:lang="en">20070108 Multiple (3) Microsoft Windows TCP/IP Remote Code Execution and DoS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019166" xml:lang="en">1019166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-2-the-case-of-the-moderate-icmp-mitigations.aspx" xml:lang="en">http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-2-the-case-of-the-moderate-icmp-mitigations.aspx</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5271" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5271" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0.2_cf2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.4::fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.4::fp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.5::fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.5::fp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:7.0.2::fp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:7.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:7.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0.2_cf2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:7.0.2::fp1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.4::fp1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.4::fp2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:7.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.5::fp1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.5::fp2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0067</vuln:cve-id>
    <vuln:published-datetime>2007-06-06T06:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:18.970-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-06-06T14:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24307" xml:lang="en">24307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21257251" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21257251</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25542" xml:lang="en">25542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/34689" xml:lang="en">domino-unspecified-dos(34689)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2046" xml:lang="en">ADV-2007-2046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35766" xml:lang="en">35766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018189" xml:lang="en">1018189</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:7.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino:7.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:7.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:7.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0068</vuln:cve-id>
    <vuln:published-datetime>2007-06-06T17:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:19.063-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-06-07T16:36:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2063" xml:lang="en">ADV-2007-2063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24322" xml:lang="en">24322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21258784" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21258784</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25520" xml:lang="en">25520</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35765" xml:lang="en">35765</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/34718" xml:lang="en">domino-signature-privilege-escalation(34718)</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0069</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T15:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-28T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T11:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5370" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5370" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-008A.html" xml:lang="en">TA08-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/115083" xml:lang="en">VU#115083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-001.mspx" xml:lang="en">MS08-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28297" xml:lang="en">28297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39453" xml:lang="en">win-ssm-mld-bo(39453)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39452" xml:lang="en">win-ssm-igmp-bo(39452)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0069" xml:lang="en">ADV-2008-0069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27100" xml:lang="en">27100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded" xml:lang="en">HPSBST02304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded" xml:lang="en">HPSBST02304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/282.html" xml:lang="en">20070108 Multiple (3) Microsoft Windows TCP/IP Remote Code Execution and DoS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019166" xml:lang="en">1019166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx" xml:lang="en">http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5370" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5370" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:air:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flex:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.115.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.39.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.35.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.34.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.24.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.63"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.25"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0::basic"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0::pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.114.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.112.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.28.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.31"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.31.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.45.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.47.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.48.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:flex:3.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.16</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.31</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.24.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.47.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.63</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.34.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0::basic</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.2</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.28.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.114.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.31.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.35.0</vuln:product>
      <vuln:product>cpe:/a:adobe:air:1.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.25</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.48.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.20</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.1</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.112.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.20.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.45.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.39.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.115.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0071</vuln:cve-id>
    <vuln:published-datetime>2008-04-09T17:05:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-04-10T10:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10379" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10379" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-150A.html" xml:lang="en">TA08-150A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-149A.html" xml:lang="en">TA08-149A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-100A.html" xml:lang="en">TA08-100A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/395473" xml:lang="en">VU#395473</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/159523" xml:lang="en">VU#159523</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/getrecord.jsp?id=37277" xml:lang="en">multimedia-file-integer-overflow(37277)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-08-032/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-08-032/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1724/references" xml:lang="en">ADV-2008-1724</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1697" xml:lang="en">ADV-2008-1697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1662/references" xml:lang="en">ADV-2008-1662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019811" xml:lang="en">1019811</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/29386" xml:lang="en">29386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28695" xml:lang="en">28695</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0221.html" xml:lang="en">RHSA-2008:0221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/44282" xml:lang="en">44282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/" xml:lang="en">http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/289.html" xml:lang="en">20080408 Adobe Flash Player Invalid Pointer Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml" xml:lang="en">GLSA-200804-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb08-11.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb08-11.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1" xml:lang="en">238305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30507" xml:lang="en">30507</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30430" xml:lang="en">30430</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30404" xml:lang="en">30404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29865" xml:lang="en">29865</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29763" xml:lang="en">29763</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html" xml:lang="en">SUSE-SA:2008:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html" xml:lang="en">APPLE-SA-2008-05-28</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isc.sans.org/diary.html?storyid=4465" xml:lang="en">http://isc.sans.org/diary.html?storyid=4465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf" xml:lang="en">http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html" xml:lang="en">http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10379" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10379" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.58</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0072</vuln:cve-id>
    <vuln:published-datetime>2008-11-17T18:30:00.313-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:26:53.670-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-11-18T11:20:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/768681" xml:lang="en">VU#768681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/38760" xml:lang="en">application-rpc-read-bo(38760)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3127" xml:lang="en">ADV-2008-3127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/32261" xml:lang="en">32261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/309.html" xml:lang="en">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32618" xml:lang="en">32618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.iss.net/archive/trend.html" xml:lang="en">http://blogs.iss.net/archive/trend.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a read operation over RPC.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.58</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0073</vuln:cve-id>
    <vuln:published-datetime>2008-11-17T18:30:00.343-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:26:53.857-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-11-18T11:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/768681" xml:lang="en">VU#768681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39050" xml:lang="en">application-rpc-file-read-bo(39050)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3127" xml:lang="en">ADV-2008-3127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/32261" xml:lang="en">32261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/309.html" xml:lang="en">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32618" xml:lang="en">32618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.iss.net/archive/trend.html" xml:lang="en">http://blogs.iss.net/archive/trend.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a file read operation over RPC.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.58</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0074</vuln:cve-id>
    <vuln:published-datetime>2008-11-17T18:30:00.360-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:26:54.030-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-11-18T11:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/768681" xml:lang="en">VU#768681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39051" xml:lang="en">application-rpc-folder-read-bo(39051)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3127" xml:lang="en">ADV-2008-3127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/32261" xml:lang="en">32261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/309.html" xml:lang="en">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32618" xml:lang="en">32618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.iss.net/archive/trend.html" xml:lang="en">http://blogs.iss.net/archive/trend.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a folder read operation over RPC.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:aspbb:aspbb"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aspbb:aspbb</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0075</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:34.170-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T10:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31230" xml:lang="en">aspbb-aspbb-info-disclosure(31230)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455683/100/0/threaded" xml:lang="en">20070102 AspBB Remote Password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.aria-security.com/forum/showthread.php?t=82" xml:lang="en">http://www.aria-security.com/forum/showthread.php?t=82</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33364" xml:lang="en">33364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2100" xml:lang="en">2100</vuln:reference>
    </vuln:references>
    <vuln:summary>AspBB stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for db/aspbb.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:2enetworx:openforum"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:2enetworx:openforum</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0076</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:34.360-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T10:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31209" xml:lang="en">openforum-openforum-password-disclosure(31209)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455684/100/0/threaded" xml:lang="en">20070102 Openforum Remote password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.aria-security.com/forum/showthread.php?t=80" xml:lang="en">http://www.aria-security.com/forum/showthread.php?t=80</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33366" xml:lang="en">33366</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2099" xml:lang="en">2099</vuln:reference>
    </vuln:references>
    <vuln:summary>Openforum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for openforum.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lblog:lblog"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lblog:lblog</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0077</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:34.577-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T10:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31229" xml:lang="en">lblog-newfolder-information-disclosure(31229)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455681/100/0/threaded" xml:lang="en">20070102 lblog Remote Password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.aria-security.com/forum/showthread.php?t=79" xml:lang="en">http://www.aria-security.com/forum/showthread.php?t=79</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017462" xml:lang="en">1017462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33367" xml:lang="en">33367</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2098" xml:lang="en">2098</vuln:reference>
    </vuln:references>
    <vuln:summary>lblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a certain file in admin/db/newFolder/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:battleblog:battleblog:1.0d"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:battleblog:battleblog:1.0d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0078</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:34.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T10:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31224" xml:lang="en">battleblog-blankmaster-info-disclosure(31224)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455614/100/0/threaded" xml:lang="en">20070101 BattleBlog Database Download Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.aria-security.com/forum/showthread.php?t=76" xml:lang="en">http://www.aria-security.com/forum/showthread.php?t=76</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33360" xml:lang="en">33360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2097" xml:lang="en">2097</vuln:reference>
    </vuln:references>
    <vuln:summary>BattleBlog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/blankmaster.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rblog:rblog"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rblog:rblog</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0079</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:35.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T11:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31200" xml:lang="en">rblog-database-info-disclosure(31200)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455626/100/0/threaded" xml:lang="en">20070101 rblog Database Download Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.aria-security.com/forum/showthread.php?t=77" xml:lang="en">http://www.aria-security.com/forum/showthread.php?t=77</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23538" xml:lang="en">23538</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32572" xml:lang="en">32572</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2102" xml:lang="en">2102</vuln:reference>
    </vuln:references>
    <vuln:summary>rblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/admin.mdb or (2) data/rblog.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:freeradius:freeradius:1.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:freeradius:freeradius:1.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0080</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:36.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T10:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31248" xml:lang="en">freeradius-smbconnectserver-bo(31248)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455678/100/0/threaded" xml:lang="en">20070102 FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455812/100/0/threaded" xml:lang="en">20070103 Re: FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.freeradius.org/security.html" xml:lang="en">http://www.freeradius.org/security.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001304.html" xml:lang="en">20070211 FreeRADIUS dispute of CVE-2007-0080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017463" xml:lang="en">1017463</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32082" xml:lang="en">32082</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance.  NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited "only to local administrators who have write access to the server configuration files."  CVE concurs with the dispute.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sunbelt:sunbelt_kerio_personal_firewall:4.3.246"/>
        <cpe-lang:fact-ref name="cpe:/a:sunbelt:sunbelt_kerio_personal_firewall:4.3.268"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sunbelt:sunbelt_kerio_personal_firewall:4.3.246</vuln:product>
      <vuln:product>cpe:/a:sunbelt:sunbelt_kerio_personal_firewall:4.3.268</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0081</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:16:58.043-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T11:03:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31232" xml:lang="en">kerio-directory-code-execution(31232)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21828" xml:lang="en">21828</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455624/100/0/threaded" xml:lang="en">20070101 Kerio Fake 'iphlpapi' DLL injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.matousec.com/info/advisories/Kerio-Fake-iphlpapi-DLL-injection.php" xml:lang="en">http://www.matousec.com/info/advisories/Kerio-Fake-iphlpapi-DLL-injection.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33356" xml:lang="en">33356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2095" xml:lang="en">2095</vuln:reference>
    </vuln:references>
    <vuln:summary>Sunbelt Kerio Personal Firewall (SKPF) 4.3.268 and 4.3.246, and possibly other versions allows local users to provide a Trojan horse iphlpapi.dll to SKPF by placing it in the installation directory.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:imgallery:imgallery:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:imgallery:imgallery:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:imgallery:imgallery:2.4</vuln:product>
      <vuln:product>cpe:/a:imgallery:imgallery:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0082</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:31.610-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T11:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31237" xml:lang="en">imgallery-start1-file-upload(31237)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0010" xml:lang="en">ADV-2007-0010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21827" xml:lang="en">21827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3049" xml:lang="en">3049</vuln:reference>
    </vuln:references>
    <vuln:summary>users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.2_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.3_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.5_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.3</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.2_beta</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.4</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.2</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.5</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.3_beta</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.7</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.5_sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0083</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:37.203-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T11:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21850" xml:lang="en">21850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455726/100/0/threaded" xml:lang="en">20070102 Nuked Klan &lt;= 1.7 Remote Cookie Disclosure Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33368" xml:lang="en">33368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2101" xml:lang="en">2101</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a getURL statement in a .swf file, as demonstrated by "Remote Cookie Disclosure."  NOTE: it could be argued that this is an issue in Shockwave instead of Nuked Klan.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:message_compiler:1.00.5239"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:message_compiler:1.00.5239</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0084</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:38.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T11:09:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455729/100/0/threaded" xml:lang="en">20070102 Windows NT Message Compiler 1.00.5239 arbitrary code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455789/100/0/threaded" xml:lang="en">20070103 Re: Windows NT Message Compiler 1.00.5239 arbitrary code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/37817" xml:lang="en">37817</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Buffer overflow in the Windows NT Message Compiler (MC) 1.00.5239 on Microsoft Windows XP allows local users to gain privileges via a long MC-filename.  NOTE: this issue has been disputed by a reliable third party who states that the compiler is not a privileged program, so privilege boundaries cannot be crossed.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:4.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0085</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:34.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T11:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata39.html#agp" xml:lang="en">[3.9] 017: SECURITY FIX: January 3, 2007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata.html#agp" xml:lang="en">[4.0] 007: SECURITY FIX: January 3, 2007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017468" xml:lang="en">1017468</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23608" xml:lang="en">23608</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31276" xml:lang="en">openbsd-vga-privilege-escalation(31276)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0043" xml:lang="en">ADV-2007-0043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=openbsd-cvs&amp;m=116785923301416&amp;w=2" xml:lang="en">[openbsd-cvs] 20070103 CVS: cvs.openbsd.org: www</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=openbsd-cvs&amp;m=116781980706409&amp;w=2" xml:lang="en">[openbsd-cvs] 20070103 Re: CVS: cvs.openbsd.org: src</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ilja.netric.org/files/Unusual%20bugs%2023c3.pdf" xml:lang="en">http://ilja.netric.org/files/Unusual%20bugs%2023c3.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32574" xml:lang="en">32574</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when the kernel is compiled with the PCIAGP option and a non-AGP device is being used, allows local users to gain privileges via unspecified vectors, possibly related to agp_ioctl NULL pointer reference.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0086</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:39.170-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T14:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455833/100/0/threaded" xml:lang="en">20070103 a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455920/100/0/threaded" xml:lang="en">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455882/100/0/threaded" xml:lang="en">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455879/100/0/threaded" xml:lang="en">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33456" xml:lang="en">33456</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0087</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:39.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T14:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455833/100/0/threaded" xml:lang="en">20070103 a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455920/100/0/threaded" xml:lang="en">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455882/100/0/threaded" xml:lang="en">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455879/100/0/threaded" xml:lang="en">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33457" xml:lang="en">33457</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openmedia:openmedia"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openmedia:openmedia</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0088</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:39.627-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T14:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31258" xml:lang="en">openmedia-page-directory-traversal(31258)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455786/100/0/threaded" xml:lang="en">20070102 openmedia local read file</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33371" xml:lang="en">33371</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33370" xml:lang="en">33370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2103" xml:lang="en">2103</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in openmedia allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) src parameter to page.php or the (2) format parameter to search_form.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:jgbbs:jgbbs:3.0:beta_1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jgbbs:jgbbs:3.0:beta_1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0089</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:39.920-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T14:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455832/100/0/threaded" xml:lang="en">20070103 jgbbs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33376" xml:lang="en">33376</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aria-security.com/forum/showthread.php?t=87" xml:lang="en">http://aria-security.com/forum/showthread.php?t=87</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31274" xml:lang="en">jgbbs-bbs-information-disclosure(31274)</vuln:reference>
    </vuln:references>
    <vuln:summary>jgbbs stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/bbs.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0090">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fermentigrafici:wineglass"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fermentigrafici:wineglass</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0090</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:46.533-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T14:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0037" xml:lang="en">ADV-2007-0037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455807/100/0/threaded" xml:lang="en">20070103 WineGlass "data.mdb" Remote Password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32575" xml:lang="en">32575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aria-security.com/forum/showthread.php?p=112" xml:lang="en">http://aria-security.com/forum/showthread.php?p=112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23594" xml:lang="en">23594</vuln:reference>
    </vuln:references>
    <vuln:summary>WineGlass stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/data.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:katy_whitton_web_development:newscmslite"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:katy_whitton_web_development:newscmslite</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0091</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:46.610-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T14:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31222" xml:lang="en">newscmslite-newscms-info-disclosure(31222)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/37548" xml:lang="en">37548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3066" xml:lang="en">3066</vuln:reference>
    </vuln:references>
    <vuln:summary>newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for newsCMS.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0092">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:e-smart_cart:e-smart_cart:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:e-smart_cart:e-smart_cart:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0092</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:46.703-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T15:09:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0036" xml:lang="en">ADV-2007-0036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23610" xml:lang="en">23610</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31679" xml:lang="en">31679</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31243" xml:lang="en">esmartcart-productdetail-sql-injection(31243)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3074" xml:lang="en">3074</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in productdetail.asp in E-SMARTCART 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cms-center:simple_web_cms"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cms-center:simple_web_cms</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0093</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:46.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T15:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31261" xml:lang="en">swcms-page-sql-injection(31261)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0040" xml:lang="en">ADV-2007-0040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455814/100/0/threaded" xml:lang="en">20070103 Simple Web Content Management System SQL Injection Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23590" xml:lang="en">23590</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31657" xml:lang="en">31657</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3076" xml:lang="en">3076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/18070102.txt" xml:lang="en">http://acid-root.new.fr/poc/18070102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2106" xml:lang="en">2106</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sven_moderow:sven_moderow_guestbook:0.3a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sven_moderow:sven_moderow_guestbook:0.3a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0094</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:42.327-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T15:13:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455788/100/0/threaded" xml:lang="en">20070103 GuestBook v0.3a Remote Password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33363" xml:lang="en">33363</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aria-security.com/forum/showthread.php?p=114" xml:lang="en">http://aria-security.com/forum/showthread.php?p=114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31245" xml:lang="en">guestbook-gbook-information-disclosure(31245)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2105" xml:lang="en">2105</vuln:reference>
    </vuln:references>
    <vuln:summary>Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.9.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.9.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0095</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:42.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T15:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31223" xml:lang="en">phpmyadmin-darkblueorange-path-disclosure(31223)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33257" xml:lang="en">33257</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051544.html" xml:lang="en">20070102 Inforamtion Discloser Vulnerabilities in  phpMyAdmin</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0034.html" xml:lang="en">20070102 Inforamtion Discloser Vulnerabilities in "phpMyAdmin"</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" xml:lang="en">MDKSA-2007:199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2104" xml:lang="en">2104</vuln:reference>
    </vuln:references>
    <vuln:summary>phpMyAdmin 2.9.1.1 allows remote attackers to obtain sensitive information via a direct request for themes/darkblue_orange/layout.inc.php, which reveals the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:carbon_communities:carbon_communities:2.4d"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:carbon_communities:carbon_communities:2.4d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0096</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:47.110-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T15:16:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31253" xml:lang="en">carboncommunities-carbon2-info-disclosure(31253)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0038" xml:lang="en">ADV-2007-0038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/37549" xml:lang="en">37549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aria-security.com/forum/showthread.php?t=85" xml:lang="en">http://aria-security.com/forum/showthread.php?t=85</vuln:reference>
    </vuln:references>
    <vuln:summary>CarbonCommunities stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for DataBase/Carbon2.4d.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:conexware:powerarchiver_2006:9.64.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:conexware:powerarchiver_2006:9.64.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0097</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:47.203-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T15:18:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://vuln.sg/powarc964-en.html" xml:lang="en">http://vuln.sg/powarc964-en.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23559" xml:lang="en">23559</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0041" xml:lang="en">ADV-2007-0041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32576" xml:lang="en">32576</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116791509125050&amp;w=2" xml:lang="en">20070104 [vuln.sg] PowerArchiver PAISO.DLL Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31263" xml:lang="en">powerarchiver-loadtree-readheader-bo(31263)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455892/100/0/threaded" xml:lang="en">20070104 [vuln.sg] PowerArchiver PAISO.DLL Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0098">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:verliadmin:verliadmin:0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:verliadmin:verliadmin:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0098</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:47.297-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-05T15:19:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0035" xml:lang="en">ADV-2007-0035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32352" xml:lang="en">32352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31241" xml:lang="en">verliadmin-language-file-include(31241)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3075" xml:lang="en">3075</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0099">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:3.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:xml_core_services:3.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0099</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:27:00.513-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-08T16:05:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5793" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5793" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-316A.html" xml:lang="en">TA08-316A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21872" xml:lang="en">21872</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS08-069.mspx" xml:lang="en">MS08-069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3111" xml:lang="en">ADV-2008-3111</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456343/100/0/threaded" xml:lang="en">20070104 Re: RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455986/100/0/threaded" xml:lang="en">20070104 RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455965/100/0/threaded" xml:lang="en">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1021164" xml:lang="en">1021164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23655" xml:lang="en">23655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/fulldisclosure/2007/Jan/0110.html" xml:lang="en">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32627" xml:lang="en">32627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=122703006921213&amp;w=2" xml:lang="en">SSRT080164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=122703006921213&amp;w=2" xml:lang="en">HPSBST02386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isc.sans.org/diary.php?storyid=2004" xml:lang="en">http://isc.sans.org/diary.php?storyid=2004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0113.html" xml:lang="en">20070104 Re: Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5793" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5793" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0100">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:perforce:perforce_client"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:perforce:perforce_client</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0100</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:43.593-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-08T16:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455977/100/0/threaded" xml:lang="en">20070104 Perforce client: security hole by design</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33369" xml:lang="en">33369</vuln:reference>
    </vuln:references>
    <vuln:summary>The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attackers to overwrite arbitrary files by modifying the client config file on the server, or by operating a malicious server.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0101">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:spine:spine:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:spine:spine:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0101</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:47.737-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-08T16:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://spine.sourceforge.net/changelog.html" xml:lang="en">http://spine.sourceforge.net/changelog.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31283" xml:lang="en">spine-unspecified-csrf(31283)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0042" xml:lang="en">ADV-2007-0042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23537" xml:lang="en">23537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32577" xml:lang="en">32577</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in SPINE allows remote attackers to perform unauthorized actions as administrators via unspecified vectors.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0102">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:preview:3.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:preview:3.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0102</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:47.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T09:46:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21910" xml:lang="en">21910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31364" xml:lang="en">multiple-vendor-pdf-code-execution(31364)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017749" xml:lang="en">1017749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24479" xml:lang="en">24479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-06-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-06-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31221" xml:lang="en">31221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:summary>The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0103">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0103</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:47.953-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T09:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31364" xml:lang="en">multiple-vendor-pdf-code-execution(31364)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017749" xml:lang="en">1017749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21910" xml:lang="en">21910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24479" xml:lang="en">24479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-06-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-06-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:summary>The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:3.0.1_pl1"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:3.0.1_pl2"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:3.0_pl2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:kde:kde:3.3.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.3</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.5</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.2</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:3.0.1_pl1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.4.3</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.4.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.4</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.1</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:3.0.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:3.0</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:3.0_pl2</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:3.0.1_pl2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0104</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T09:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-964" xml:lang="en">https://issues.rpath.com/browse/RPL-964</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31364" xml:lang="en">multiple-vendor-pdf-code-execution(31364)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0244" xml:lang="en">ADV-2007-0244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0212" xml:lang="en">ADV-2007-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0203" xml:lang="en">ADV-2007-0203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-410-2" xml:lang="en">USN-410-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-410-1" xml:lang="en">USN-410-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017749" xml:lang="en">1017749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21910" xml:lang="en">21910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/457055/100/0/threaded" xml:lang="en">20070116 [KDE Security Advisory] kpdf/kword/xpdf denial of service vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_3_sr.html" xml:lang="en">SUSE-SR:2007:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:024" xml:lang="en">MDKSA-2007:024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:022" xml:lang="en">MDKSA-2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:021" xml:lang="en">MDKSA-2007:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:020" xml:lang="en">MDKSA-2007:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:019" xml:lang="en">MDKSA-2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:018" xml:lang="en">MDKSA-2007:018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20070115-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20070115-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.html" xml:lang="en">http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017514" xml:lang="en">1017514</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24479" xml:lang="en">24479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24204" xml:lang="en">24204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23876" xml:lang="en">23876</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23844" xml:lang="en">23844</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23839" xml:lang="en">23839</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23815" xml:lang="en">23815</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23813" xml:lang="en">23813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23808" xml:lang="en">23808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23799" xml:lang="en">23799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23791" xml:lang="en">23791</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-06-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-06-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:summary>The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0105">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:4.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0105</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:48.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T09:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/744249" xml:lang="en">VU#744249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23629" xml:lang="en">23629</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31323" xml:lang="en">cisco-acs-csadmin-bo(31323)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0068" xml:lang="en">ADV-2007-0068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21900" xml:lang="en">21900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070105-csacs.shtml" xml:lang="en">20070105 Multiple Vulnerabilities in Cisco Secure Access Control Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017475" xml:lang="en">1017475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32642" xml:lang="en">32642</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0106">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.5</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.4</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.3</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0106</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:48.377-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T09:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21893" xml:lang="en">21893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wordpress.org/development/2007/01/wordpress-206/" xml:lang="en">http://wordpress.org/development/2007/01/wordpress-206/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0061" xml:lang="en">ADV-2007-0061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456048/100/0/threaded" xml:lang="en">20070105 Advisory 01/2007: WordPress CSRF Protection XSS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hardened-php.net/advisory_012007.140.html" xml:lang="en">http://www.hardened-php.net/advisory_012007.140.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23595" xml:lang="en">23595</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33397" xml:lang="en">33397</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2114" xml:lang="en">2114</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token and quote characters or HTML tags in URL variable names, which are not properly handled when WordPress generates a new link to verify the request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0107</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:48.500-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T09:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31297" xml:lang="en">wordpress-mbstring-security-bypass(31297)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21907" xml:lang="en">21907</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456049/100/0/threaded" xml:lang="en">20070105 Advisory 02/2007: WordPress Trackback Charset Decoding SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.005.html" xml:lang="en">OpenPKG-SA-2007.005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hardened-php.net/advisory_022007.141.html" xml:lang="en">http://www.hardened-php.net/advisory_022007.141.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wordpress.org/development/2007/01/wordpress-206/" xml:lang="en">http://wordpress.org/development/2007/01/wordpress-206/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23595" xml:lang="en">23595</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0061" xml:lang="en">ADV-2007-0061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31579" xml:lang="en">31579</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2112" xml:lang="en">2112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-10.xml" xml:lang="en">GLSA-200701-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23741" xml:lang="en">23741</vuln:reference>
    </vuln:references>
    <vuln:summary>WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:novell:client:4.91:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:client:4.91:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0108</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:48.597-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31343" xml:lang="en">novell-profile-security-bypass(31343)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0064" xml:lang="en">ADV-2007-0064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21886" xml:lang="en">21886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974970.htm" xml:lang="en">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974970.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017471" xml:lang="en">1017471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23619" xml:lang="en">23619</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31358" xml:lang="en">31358</vuln:reference>
    </vuln:references>
    <vuln:summary>nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.5</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.4</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.3</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0109</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:48.703-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T09:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31262" xml:lang="en">wordpress-account-enumeration(31262)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0062" xml:lang="en">ADV-2007-0062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455927/100/0/threaded" xml:lang="en">20070103 Wordpress &lt;= 2.x dictionnary &amp; Bruteforce attack</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23621" xml:lang="en">23621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31577" xml:lang="en">31577</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2113" xml:lang="en">2113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-10.xml" xml:lang="en">GLSA-200701-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23741" xml:lang="en">23741</vuln:reference>
    </vuln:references>
    <vuln:summary>wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:novell:access_manager_identity_server:3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:access_manager_identity_server:3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0110</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:48.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://secure-support.novell.com/KanisaPlatform/Publishing/143/3615264_f.SAL_Public.html" xml:lang="en">https://secure-support.novell.com/KanisaPlatform/Publishing/143/3615264_f.SAL_Public.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0073" xml:lang="en">ADV-2007-0073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21921" xml:lang="en">21921</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23654" xml:lang="en">23654</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31359" xml:lang="en">31359</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017483" xml:lang="en">1017483</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject arbitrary web script or HTML via the IssueInstant parameter, which is not properly handled in the resulting error message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:resco:photo_viewer:4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:resco:photo_viewer:6.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:resco:photo_viewer:6.11</vuln:product>
      <vuln:product>cpe:/a:resco:photo_viewer:4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0111</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:48.953-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0072" xml:lang="en">ADV-2007-0072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+Resco+Photo+Viewer+6%2E01+Enabling+Code+Injection+and+Arbitrary+Code+Execution" xml:lang="en">http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+Resco+Photo+Viewer+6%2E01+Enabling+Code+Injection+and+Arbitrary+Code+Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21920" xml:lang="en">21920</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23658" xml:lang="en">23658</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32644" xml:lang="en">32644</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blog.trendmicro.com/flaw-in-3rd-party-app-weakens-windows-mobile/" xml:lang="en">http://blog.trendmicro.com/flaw-in-3rd-party-app-weakens-windows-mobile/</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Resco Photo Viewer for PocketPC 4.11 and 6.01, as used in mobile devices running Windows Mobile 5.0, 2003, and 2003SE, allows remote attackers to execute arbitrary code via a crafted PNG image.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:createauction:createauction"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:createauction:createauction</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0112</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:49.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31356" xml:lang="en">createauction-cats-sql-injection(31356)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21929" xml:lang="en">21929</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456272/100/0/threaded" xml:lang="en">20070107 createauction (cats.asp) Remote SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33406" xml:lang="en">33406</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2111" xml:lang="en">2111</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in cats.asp in createauction allows remote attackers to execute arbitrary SQL commands via the catid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:packeteer:packetwise:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:packeteer:packetwise:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0113</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:49.157-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:16:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31357" xml:lang="en">packetshaper-argument-dos(31357)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0098" xml:lang="en">ADV-2007-0098</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21933" xml:lang="en">21933</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456267/100/0/threaded" xml:lang="en">20070108 Packeteer PacketWise CLI overflow DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23685" xml:lang="en">23685</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31656" xml:lang="en">31656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2110" xml:lang="en">2110</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Packeteer PacketShaper PacketWise 8.x allows remote authenticated users to cause a denial of service (reset or reboot) via (1) a long traffic class argument to the "class show" command or (2) a long POLICY parameter value in clastree.htm.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:java_system_content_delivery_server:5.0::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java_system_content_delivery_server:5.0:pu1:solaris"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:java_system_content_delivery_server:5.0::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:java_system_content_delivery_server:5.0:pu1:solaris</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0114</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:49.267-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102764-1" xml:lang="en">102764</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23630" xml:lang="en">23630</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31345" xml:lang="en">sun-java-cds-info-disclosure(31345)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0076" xml:lang="en">ADV-2007-0076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21908" xml:lang="en">21908</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32645" xml:lang="en">32645</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun Java System Content Delivery Server 5.0 and 5.0 PU1 allows remote attackers to obtain sensitive information regarding "content details" via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.4.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.4.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0115</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:49.983-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:13:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456051/100/0/threaded" xml:lang="en">20070105 Coppermine Photo Gallery &lt;= 1.4.10 SQL Injection Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001218.html" xml:lang="en">20070108 Source verify - Coppermine Photo Gallery &lt;= 1.4.10 code injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33383" xml:lang="en">33383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/19070104.txt" xml:lang="en">http://acid-root.new.fr/poc/19070104.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2107" xml:lang="en">2107</vuln:reference>
    </vuln:references>
    <vuln:summary>Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0116">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digger_solutions:intranet_open_source"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digger_solutions:intranet_open_source</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0116</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:50.627-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456047/100/0/threaded" xml:lang="en">20070105 Intranet Open Source Remote Password Disclosure "intranet.mdb"</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33379" xml:lang="en">33379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31308" xml:lang="en">intranet-intranet-info-disclosure(31308)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2109" xml:lang="en">2109</vuln:reference>
    </vuln:references>
    <vuln:summary>Digger Solutions Intranet Open Source (IOS) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for data/intranet.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0117">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0117</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:49.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:20:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0074" xml:lang="en">ADV-2007-0074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21899" xml:lang="en">21899</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-05-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-05-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31167" xml:lang="en">31167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23653" xml:lang="en">23653</vuln:reference>
    </vuln:references>
    <vuln:summary>DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permission changes upon execution of a diskutil permission repair operation.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:edittag:edittag:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:edittag:edittag:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0118</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:51.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21890" xml:lang="en">21890</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456055/100/0/threaded" xml:lang="en">20070105 Multiple bugs in EditTag</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33396" xml:lang="en">33396</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33395" xml:lang="en">33395</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33394" xml:lang="en">33394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33393" xml:lang="en">33393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/7950" xml:lang="en">7950</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:edittag:edittag:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:edittag:edittag:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0119</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:51.267-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21891" xml:lang="en">21891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456055/100/0/threaded" xml:lang="en">20070105 Multiple bugs in EditTag</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33392" xml:lang="en">33392</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33391" xml:lang="en">33391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33390" xml:lang="en">33390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/7950" xml:lang="en">7950</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script or HTML via the plain parameter to (1) mkpw_mp.cgi, (2) mkpw.pl, or (3) mkpw.cgi.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:acunetix:web_vulnerability_scanner:4.0_build_2006-07-17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:acunetix:web_vulnerability_scanner:4.0_build_2006-07-17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0120</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:50.033-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31279" xml:lang="en">acunetix-content-length-dos(31279)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21898" xml:lang="en">21898</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/37580" xml:lang="en">37580</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3078" xml:lang="en">3078</vuln:reference>
    </vuln:references>
    <vuln:summary>Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of service (application crash) via multiple HTTP requests containing invalid Content-Length values.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0121">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:michael_romedahl:ri_blog:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michael_romedahl:ri_blog:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0121</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:50.110-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T10:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0083" xml:lang="en">ADV-2007-0083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21880" xml:lang="en">21880</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456052/100/0/threaded" xml:lang="en">20070105 RI Blog 1.3 XSS Vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31637" xml:lang="en">31637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31317" xml:lang="en">riblog-search-xss(31317)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2108" xml:lang="en">2108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23657" xml:lang="en">23657</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.0_rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.1_beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.2.2_b"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.2.2_b-nuke"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.4.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.1</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.2.2_b</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.2.1</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.3.2</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.0</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.2</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.4.10</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.3.3</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.3</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.3.4</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.4.9</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.2.2_b-nuke</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.1_beta_2</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.4.4</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.0_rc3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0122</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:52.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T00:34:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21894" xml:lang="en">21894</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456051/100/0/threaded" xml:lang="en">20070105 Coppermine Photo Gallery &lt;= 1.4.10 SQL Injection Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35856" xml:lang="en">35856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35855" xml:lang="en">35855</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35854" xml:lang="en">35854</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35853" xml:lang="en">35853</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35852" xml:lang="en">35852</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/19070104.txt" xml:lang="en">http://acid-root.new.fr/poc/19070104.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2123" xml:lang="en">2123</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25846" xml:lang="en">25846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3085" xml:lang="en">3085</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:uber_uploader:uber_uploader:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:uber_uploader:uber_uploader:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0123</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:17:04.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T11:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456045/100/0/threaded" xml:lang="en">20070105 Uber Uploader 4.2 Arbitrary File Upload Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31303" xml:lang="en">uber-uploader-phtml-file-upload(31303)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2116" xml:lang="en">2116</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in Uber Uploader 4.2 allows remote attackers to upload and execute arbitrary PHP scripts by naming them with a .phtml extension, which bypasses the .php extension check but is still executable on some server configurations.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:drupal:4.7.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.9</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.10</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.6</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.8</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.7</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0124</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:50.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T11:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21895" xml:lang="en">21895</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456056/100/0/threaded" xml:lang="en">20070105 [DRUPAL-SA-2007-002] Drupal 4.6.11 / 4.7.5 fixes DoS issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23586" xml:lang="en">23586</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/104238" xml:lang="en">http://drupal.org/node/104238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0051" xml:lang="en">ADV-2007-0051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32131" xml:lang="en">32131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2115" xml:lang="en">2115</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_antivirus_engine:5.5.10::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_antivirus_engine:6.0::windows"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_antivirus_engine:5.5.10::linux</vuln:product>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_antivirus_engine:6.0::windows</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0125</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:50.437-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T11:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31315" xml:lang="en">kaspersky-antivirus-pe-dos(31315)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0067" xml:lang="en">ADV-2007-0067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21901" xml:lang="en">21901</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017476" xml:lang="en">1017476</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23575" xml:lang="en">23575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32588" xml:lang="en">32588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=459" xml:lang="en">20070105 Kaspersky Antivirus Scan Engine PE File Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Kaspersky Labs Antivirus Engine 6.0 for Windows and 5.5-10 for Linux before 20070102 enter an infinite loop upon encountering an invalid NumberOfRvaAndSizes value in the Optional Windows Header of a portable executable (PE) file, which allows remote attackers to cause a denial of service (CPU consumption) by scanning a crafted PE file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera:opera_browser:9.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0126</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T11:13:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.opera.com/support/search/supsearch.dml?index=852" xml:lang="en">http://www.opera.com/support/search/supsearch.dml?index=852</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31305" xml:lang="en">opera-jpeg-dht-bo(31305)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0060" xml:lang="en">ADV-2007-0060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml" xml:lang="en">GLSA-200701-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017473" xml:lang="en">1017473</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23771" xml:lang="en">23771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23739" xml:lang="en">23739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23613" xml:lang="en">23613</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31574" xml:lang="en">31574</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html" xml:lang="en">SUSE-SA:2007:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457" xml:lang="en">20070105 Opera Software Opera Web Browser JPG Image DHT Marker Heap Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bytes in the Define Huffman Table (DHT) marker.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.02"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.01"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.54"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.01"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.51"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.53"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.02"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.50"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.52"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.54:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.54:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.52"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.51"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.50"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.20"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.21"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.22"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.50:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.53"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.03"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.54"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.10"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.11"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.23"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.20:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.01"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.60"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.02"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.0:beta1_v2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.11:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.10:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.1:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.06"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.05"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.04"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.03"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.02"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.01"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.0:tp3"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.0:tp2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.0:tp1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta8"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.02"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.00"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.02"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.00:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.01"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.00:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.00:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.00:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.00:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.62"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.62:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.60"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.61"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.50"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.51"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.21"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.00"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.00:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:2.10:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:2.10:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:2.10:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:2.00"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:1.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera:opera_browser:9.02</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.02</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.00:beta</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.00:beta5</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.03</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:2.12</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.53</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.10</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.62:beta</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.00:beta3</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.0:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.60</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.12</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta5</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.11</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:2.10:beta3</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.0:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.06</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta4</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.12</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.00:beta4</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.11</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.54</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.52</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta6</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.01</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.23</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.1:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.22</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.01</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.0:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.0</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.05</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.0:beta3</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.00</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.00:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.21</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.50</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.10</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.11:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.03</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.11</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta7</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.21</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.00</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.0:beta1_v2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.0</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.54:update1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.54:update2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.51</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.10:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.62</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.0:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.02</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.01</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.02</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.0</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:2.10:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.0:tp2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.01</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.04</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta8</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.02</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.53</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.00:beta6</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.50</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.01</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.51</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.0</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:2.10:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.0:tp1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta3</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.0:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.51</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:2.10</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.61</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.52</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.20:beta7</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.0:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.0:tp3</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.10</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.54</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:1.00</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:2.00</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.50:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.50</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.0:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.20</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.0:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.02</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.60</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0127</vuln:cve-id>
    <vuln:discovered-datetime>2006-11-16T00:00:00.000-05:00</vuln:discovered-datetime>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T17:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23613" xml:lang="en">23613</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458" xml:lang="en">20070105 Opera Software Opera Web Browser createSVGTransformFromMatrix Object Typecasting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0060" xml:lang="en">ADV-2007-0060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.opera.com/support/search/supsearch.dml?index=851" xml:lang="en">http://www.opera.com/support/search/supsearch.dml?index=851</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml" xml:lang="en">GLSA-200701-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017473" xml:lang="en">1017473</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23771" xml:lang="en">23771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23739" xml:lang="en">23739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31575" xml:lang="en">31575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html" xml:lang="en">SUSE-SA:2007:009</vuln:reference>
    </vuln:references>
    <vuln:summary>The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0128">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digiappz:digirez:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digiappz:digirez:3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0128</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:50.737-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T13:20:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0053" xml:lang="en">ADV-2007-0053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23606" xml:lang="en">23606</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31677" xml:lang="en">31677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3081" xml:lang="en">3081</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:locazo:locazolist_classifieds:2.01a_beta5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:locazo:locazolist_classifieds:2.01a_beta5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0129</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:50.830-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T13:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31242" xml:lang="en">locazolist-main-sql-injection(31242)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0052" xml:lang="en">ADV-2007-0052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35813" xml:lang="en">35813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3073" xml:lang="en">3073</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatID parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0130">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:igeneric:ig_calendar:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:igeneric:ig_calendar:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0130</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:50.937-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T13:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0055" xml:lang="en">ADV-2007-0055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21873" xml:lang="en">21873</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23602" xml:lang="en">23602</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31678" xml:lang="en">31678</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31300" xml:lang="en">igcalendar-user-sql-injection(31300)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456044/100/0/threaded" xml:lang="en">20070105 IG Calendar SQL Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3082" xml:lang="en">3082</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in user.php in iGeneric iG Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:jamwiki:jamwiki:0.4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jamwiki:jamwiki:0.4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0131</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:54.280-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T13:31:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=171441&amp;release_id=475663" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=171441&amp;release_id=475663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23634" xml:lang="en">23634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32581" xml:lang="en">32581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31296" xml:lang="en">jamwiki-permission-security-bypass(31296)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21879" xml:lang="en">21879</vuln:reference>
    </vuln:references>
    <vuln:summary>JAMWiki before 0.5.0 does not properly check permissions during moves of "read-only or admin-only topics," which allows remote attackers to make unauthorized changes to the wiki.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0132">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:igeneric:ig_shop:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:igeneric:ig_shop:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0132</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:51.110-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T13:33:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0056" xml:lang="en">ADV-2007-0056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23604" xml:lang="en">23604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt" xml:lang="en">http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33385" xml:lang="en">33385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31299" xml:lang="en">igshop-compareproduct-sql-injection(31299)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21874" xml:lang="en">21874</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456043/100/0/threaded" xml:lang="en">20070105 IG Shop remote code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3083" xml:lang="en">3083</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in compare_product.php in iGeneric iG Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:igeneric:ig_shop:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:igeneric:ig_shop:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0133</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:51.220-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T13:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0056" xml:lang="en">ADV-2007-0056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33386" xml:lang="en">33386</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in display_review.php in iGeneric iG Shop 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) user_login_cookie parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:igeneric:ig_shop:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:igeneric:ig_shop:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:igeneric:ig_shop:1.0</vuln:product>
      <vuln:product>cpe:/a:igeneric:ig_shop:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0134</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-13T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T13:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31301" xml:lang="en">igshop-cartpage-code-execution(31301)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0056" xml:lang="en">ADV-2007-0056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21875" xml:lang="en">21875</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/471722/100/0/threaded" xml:lang="en">20070619 iG Shop 1.4 eval Inclusion Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456043/100/0/threaded" xml:lang="en">20070105 IG Shop remote code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-June/001664.html" xml:lang="en">20070618 Dup: iG Shop 1.4 (page.php) Remote Code Execution Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23604" xml:lang="en">23604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt" xml:lang="en">http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33388" xml:lang="en">33388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33387" xml:lang="en">33387</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3083" xml:lang="en">3083</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php.  NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:aratix:aratix:0.2.2_beta_11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aratix:aratix:0.2.2_beta_11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0135</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:51.407-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T13:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0054" xml:lang="en">ADV-2007-0054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001219.html" xml:lang="en">20070108 Source verify of Aratix RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityreason.com/exploitalert/1698" xml:lang="en">http://securityreason.com/exploitalert/1698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33405" xml:lang="en">33405</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31282" xml:lang="en">aratix-init-file-include(31282)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3079" xml:lang="en">3079</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the current_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:drupal:4.7.4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0136</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:51.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T13:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/104233" xml:lang="en">http://drupal.org/node/104233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0050" xml:lang="en">ADV-2007-0050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32140" xml:lang="en">32140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32139" xml:lang="en">32139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116799778408115&amp;w=2" xml:lang="en">20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31311" xml:lang="en">drupal-core-unspecified-xss(31311)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456054/100/100/threaded" xml:lang="en">20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes XSS issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/files/sa-2007-001/advisory.txt" xml:lang="en">http://drupal.org/files/sa-2007-001/advisory.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:serendipitynz:serene_bach:1.18r"/>
        <cpe-lang:fact-ref name="cpe:/a:serendipitynz:serene_bach:2.05r"/>
        <cpe-lang:fact-ref name="cpe:/a:serendipitynz:serene_bach:2.08d"/>
        <cpe-lang:fact-ref name="cpe:/a:serendipitynz:serene_bach_sb:1.13d"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:serendipitynz:serene_bach:1.18r</vuln:product>
      <vuln:product>cpe:/a:serendipitynz:serene_bach:2.05r</vuln:product>
      <vuln:product>cpe:/a:serendipitynz:serene_bach:2.08d</vuln:product>
      <vuln:product>cpe:/a:serendipitynz:serene_bach_sb:1.13d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0137</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:51.627-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T13:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23623" xml:lang="en">23623</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0065" xml:lang="en">ADV-2007-0065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://serenebach.net/log/sb209R.html" xml:lang="en">http://serenebach.net/log/sb209R.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://serenebach.net/log/sb119R.html" xml:lang="en">http://serenebach.net/log/sb119R.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32580" xml:lang="en">32580</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/jp/JVN%2365500885/index.html" xml:lang="en">JVN#65500885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31302" xml:lang="en">serene-bach-unspecified-xss(31302)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21884" xml:lang="en">21884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017470" xml:lang="en">1017470</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in SimpleBoxes/SerendipityNZ Serene Bach 2.05R and earlier, and 2.08D and earlier in the 2.08 series; and (2) sb 1.13D and earlier, and 1.18R and earlier in the 1.18 series; allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fersch:formbankserver:1.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fersch:formbankserver:1.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0138</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:57.420-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T13:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31216" xml:lang="en">formbankserver-formbank-dos(31216)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23539" xml:lang="en">23539</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32546" xml:lang="en">32546</vuln:reference>
    </vuln:references>
    <vuln:summary>formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with (1) AbfrageForm or (2) EingabeForm, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ sequences in the Name parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:openvms:7.3::openvms_vax"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openvms:7.3_2::openvms_vax"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:openvms:7.3::openvms_vax</vuln:product>
      <vuln:product>cpe:/a:hp:openvms:7.3_2::openvms_vax</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0139</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:51.847-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T07:09:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23636" xml:lang="en">23636</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.itrc.hp.com/openvms_patches/vax/V7.3/VAX_DNVOSIMUP01-V0703.txt" xml:lang="en">ftp://ftp.itrc.hp.com/openvms_patches/vax/V7.3/VAX_DNVOSIMUP01-V0703.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIMUP01-V0703-2.txt" xml:lang="en">ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIMUP01-V0703-2.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0063" xml:lang="en">ADV-2007-0063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32586" xml:lang="en">32586</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32585" xml:lang="en">32585</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32584" xml:lang="en">32584</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32583" xml:lang="en">32583</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the DECnet-Plus 7.3-2 feature in DECnet/OSI 7.3-2 for OpenVMS ALPHA, and the DECnet-Plus 7.3 feature in DECnet/OSI 7.3 for OpenVMS VAX, allows attackers to obtain "unintended privileged access to data and system resources" via unspecified vectors, related to (1) [SYSEXE]CTF$UI.EXE, (2) [SYSMSG]CTF$MESSAGES.EXE, (3) [SYSHLP]CTF$HELP.HLB, and (4) [SYSMGR]CTF$STARTUP.COM.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0140">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:kolayindir_download:kolayindir_download"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kolayindir_download:kolayindir_download</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0140</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:51.953-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T14:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0079" xml:lang="en">ADV-2007-0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21889" xml:lang="en">21889</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456068/100/0/threaded" xml:lang="en">20070105 Kolayindir Download (Yenionline) (tr) SqL Injection Vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23645" xml:lang="en">23645</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31625" xml:lang="en">31625</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31320" xml:lang="en">kolayindirdownload-down-sql-injection(31320)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2122" xml:lang="en">2122</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in down.asp in Kolayindir Download (Yenionline) allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:yet_another_link_directory:yet_another_link_directory:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yet_another_link_directory:yet_another_link_directory:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0141</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:52.047-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T14:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0082" xml:lang="en">ADV-2007-0082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21904" xml:lang="en">21904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456122/100/0/threaded" xml:lang="en">20070106 Yet Another Link Directory v1.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23646" xml:lang="en">23646</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31626" xml:lang="en">31626</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31322" xml:lang="en">yald-yald-xss(31322)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2121" xml:lang="en">2121</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in yald.php in Yet Another Link Directory 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:shopstorenow:e-commerce_shopping_cart"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:shopstorenow:e-commerce_shopping_cart</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0142</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:52.157-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T14:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0080" xml:lang="en">ADV-2007-0080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21905" xml:lang="en">21905</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456127/100/0/threaded" xml:lang="en">20070106 shopstorenow (orange.asp) sql injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23642" xml:lang="en">23642</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31665" xml:lang="en">31665</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31313" xml:lang="en">shopstorenow-orange-sql-injection(31313)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2120" xml:lang="en">2120</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nune:news_script:2.0_pre2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nune:news_script:2.0_pre2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0143</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:52.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T14:20:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0078" xml:lang="en">ADV-2007-0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23635" xml:lang="en">23635</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31209" xml:lang="en">31209</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31208" xml:lang="en">31208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3090" xml:lang="en">3090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31312" xml:lang="en">nune-index-archives-file-include(31312)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456242/100/0/threaded" xml:lang="en">20070107 NUNE News Script (custom_admin_path) Remote File Include Vulnerablity</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitrary PHP code via a URL in the custom_admin_path parameter to (1) index.php or (2) archives.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0144">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digitizing_quote_and_ordering_system:digitizing_quote_and_ordering_system:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digitizing_quote_and_ordering_system:digitizing_quote_and_ordering_system:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0144</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:52.360-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T14:23:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23652" xml:lang="en">23652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31690" xml:lang="en">31690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31321" xml:lang="en">qos-search-xss(31321)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3089" xml:lang="en">3089</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bingo_news:bingo_news:3.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bingo_news:bingo_news:3.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0145</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:59.267-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T14:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017477" xml:lang="en">1017477</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35898" xml:lang="en">35898</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31328" xml:lang="en">bingo-bnsmrep1-file-include(31328)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in bn_smrep1.php in BinGoPHP News (BP News) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter, a different vector than CVE-2006-4648 and CVE-2006-4649.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0146">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fix_and_chips_computer_services:fix_and_chips_cms:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fix_and_chips_computer_services:fix_and_chips_cms:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0146</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:52.533-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T14:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0081" xml:lang="en">ADV-2007-0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456121/100/0/threaded" xml:lang="en">20070106 Fix &amp; Chips CMS v1.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23625" xml:lang="en">23625</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31319" xml:lang="en">fixandchips-multiple-scripts-xss(31319)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32650" xml:lang="en">32650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32649" xml:lang="en">32649</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32648" xml:lang="en">32648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32647" xml:lang="en">32647</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32646" xml:lang="en">32646</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2119" xml:lang="en">2119</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Fix and Chips CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) delete-announce.php; the (2) Announcement form field in (b) staff.php; the (3) Client Name, (4) Business Name, (5) Street, (6) Address 2, (7) Town/City, (8) Postcode, (9) Phone Number, (10) Email Address and (11) Website Address form fields in (c) new_customer.php; and unspecified fields in (d) search.php and (e) client-results.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0147">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cuyahoga:cuyahoga:1.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cuyahoga:cuyahoga:1.0.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0147</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:59.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T14:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.cuyahoga-project.org/10/section.aspx/61" xml:lang="en">http://www.cuyahoga-project.org/10/section.aspx/61</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23662" xml:lang="en">23662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cuyahoga.svn.sourceforge.net/viewvc/cuyahoga?view=rev&amp;revision=551" xml:lang="en">http://cuyahoga.svn.sourceforge.net/viewvc/cuyahoga?view=rev&amp;revision=551</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32643" xml:lang="en">32643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21927" xml:lang="en">21927</vuln:reference>
    </vuln:references>
    <vuln:summary>Cuyahoga before 1.0.1 installs the FCKEditor component with an incorrect deny statement in a Web.config file, which allows remote attackers to upload files when these privileges were intended only for the Administrator and Editor roles.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0148">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:omnigroup:omniweb:5.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:omnigroup:omniweb:5.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0148</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:52.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T14:34:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.omnigroup.com/applications/omniweb/releasenotes/" xml:lang="en">http://www.omnigroup.com/applications/omniweb/releasenotes/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23624" xml:lang="en">23624</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0075" xml:lang="en">ADV-2007-0075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-07-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-07-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31222" xml:lang="en">31222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31324" xml:lang="en">omniweb-alert-format-string(31324)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21911" xml:lang="en">21911</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456578/100/0/threaded" xml:lang="en">20070111 DMA[2007-0107a] OmniWeb Javascript Alert Format String Vulnerabiity and DMA[2007-0109a] Apple Finder Disk Image Volume Label Overflow / DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalmunition.com/DMA%5B2007-0107a%5D.txt" xml:lang="en">http://www.digitalmunition.com/DMA%5B2007-0107a%5D.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3098" xml:lang="en">3098</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://blog.omnigroup.com/2007/01/07/omniweb-552-now-available-and-more-secure/" xml:lang="en">http://blog.omnigroup.com/2007/01/07/omniweb-552-now-available-and-more-secure/</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the Javascript alert function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0149">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ememberspro:ememberspro:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ememberspro:ememberspro:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0149</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:00.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T14:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456228/100/0/threaded" xml:lang="en">20070107 EMembersPro 1.0 Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33403" xml:lang="en">33403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31329" xml:lang="en">ememberspro-users-info-disclosure(31329)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2118" xml:lang="en">2118</vuln:reference>
    </vuln:references>
    <vuln:summary>EMembersPro 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for users.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0150">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:dayfox_designs:dayfox_blog:4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dayfox_designs:dayfox_blog:4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0150</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:52.907-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T14:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0099" xml:lang="en">ADV-2007-0099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456212/100/0/threaded" xml:lang="en">20070107 Dayfox Blog Remote File Include Vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31259" xml:lang="en">31259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31336" xml:lang="en">dayfoxblog-index-file-include(31336)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2117" xml:lang="en">2117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23661" xml:lang="en">23661</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in index.php in Dayfox Blog allow remote attackers to execute arbitrary PHP code via a URL in the (1) page, (2) subject, and (3) q parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0151">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mitisoft:mitisoft"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mitisoft:mitisoft</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0151</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:01.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T15:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456230/100/0/threaded" xml:lang="en">20070107 MitiSoft Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33409" xml:lang="en">33409</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31341" xml:lang="en">mitisoft-mitisoft-info-disclosure(31341)</vuln:reference>
    </vuln:references>
    <vuln:summary>MitiSoft stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for access_MS/MitiSoft.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0152">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ohhasp:ohhasp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ohhasp:ohhasp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0152</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:01.170-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T15:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456117/100/0/threaded" xml:lang="en">20070106 ohhASP Remote Password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33381" xml:lang="en">33381</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://64.38.62.221/ariasecucom/forum/showthread.php?t=89" xml:lang="en">http://64.38.62.221/ariasecucom/forum/showthread.php?t=89</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31342" xml:lang="en">ohhasp-ohhasp-info-disclosure(31342)</vuln:reference>
    </vuln:references>
    <vuln:summary>OhhASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/OhhASP.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0153">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adam_jarret:ajlogin:3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adam_jarret:ajlogin:3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0153</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:01.390-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T15:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456226/100/0/threaded" xml:lang="en">20070107 AJLogin v3.5 Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33404" xml:lang="en">33404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31331" xml:lang="en">ajlogin-ajlogin-info-disclosure(31331)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2127" xml:lang="en">2127</vuln:reference>
    </vuln:references>
    <vuln:summary>AJLogin 3.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for ajlogin.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0154">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:webulas:webulas"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webulas:webulas</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0154</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:01.797-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T15:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456239/100/0/threaded" xml:lang="en">20070107 Webulas Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33401" xml:lang="en">33401</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31338" xml:lang="en">webulas-db-info-disclosure(31338)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2126" xml:lang="en">2126</vuln:reference>
    </vuln:references>
    <vuln:summary>Webulas stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/db.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:harikaonline:harikaonline:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:harikaonline:harikaonline:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0155</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:02.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T15:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456238/100/0/threaded" xml:lang="en">20070107 HarikaOnline v2.0 Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33410" xml:lang="en">33410</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31339" xml:lang="en">harikaonline-harikaonline-info-disclosure(31339)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2125" xml:lang="en">2125</vuln:reference>
    </vuln:references>
    <vuln:summary>HarikaOnline 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for harikaonline.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:m-core:m-core"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:m-core:m-core</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0156</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:02.360-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T15:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456235/100/0/threaded" xml:lang="en">20070107 M-Core Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33402" xml:lang="en">33402</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31340" xml:lang="en">mcore-uyelik-info-disclosure(31340)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2124" xml:lang="en">2124</vuln:reference>
    </vuln:references>
    <vuln:summary>M-Core stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to db/uyelik.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0157">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:neon:neon:0.26.0"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon:0.26.1"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon:0.26.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:neon:neon:0.26.2</vuln:product>
      <vuln:product>cpe:/a:neon:neon:0.26.1</vuln:product>
      <vuln:product>cpe:/a:neon:neon:0.26.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0157</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:53.487-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T16:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0362" xml:lang="en">ADV-2007-0362</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0172" xml:lang="en">ADV-2007-0172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/39247" xml:lang="en">39247</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://mailman.webdav.org/pipermail/neon/2007-January/002362.html" xml:lang="en">[neon] 20070107 invalid chars cause sigserv in neon</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.webdav.org/cadaver/" xml:lang="en">http://www.webdav.org/cadaver/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22035" xml:lang="en">22035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_02_sr.html" xml:lang="en">SUSE-SR:2007:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:013" xml:lang="en">MDKSA-2007:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23984" xml:lang="en">23984</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23763" xml:lang="en">23763</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23751" xml:lang="en">23751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html" xml:lang="en">[cadaver] 20070123 release 0.22.5</vuln:reference>
    </vuln:references>
    <vuln:summary>Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0159">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:geoip:geoip:1.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:geoip:geoip:1.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0159</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:53.610-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T09:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://arctic.org/~dean/patches/GeoIP-1.4.0-update-vulnerability.patch" xml:lang="en">http://arctic.org/~dean/patches/GeoIP-1.4.0-update-vulnerability.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0118" xml:lang="en">ADV-2007-0118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0117" xml:lang="en">ADV-2007-0117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31618" xml:lang="en">31618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31383" xml:lang="en">geoip-geoipupdate-directory-traversal(31383)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-412-1" xml:lang="en">USN-412-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21959" xml:lang="en">21959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:004" xml:lang="en">MDKSA-2007:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23906" xml:lang="en">23906</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23880" xml:lang="en">23880</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the GeoIP_update_database_general function in libGeoIP/GeoIPUpdate.c in GeoIP 1.4.0 allows remote malicious update servers (possibly only update.maxmind.com) to overwrite arbitrary files via a .. (dot dot) in the database filename, which is returned by a request to app/update_getfilename.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0160">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.13"/>
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.14"/>
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.20"/>
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.21"/>
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.9.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:centericq:centericq:4.14</vuln:product>
      <vuln:product>cpe:/a:centericq:centericq:4.13</vuln:product>
      <vuln:product>cpe:/a:centericq:centericq:4.20</vuln:product>
      <vuln:product>cpe:/a:centericq:centericq:4.12</vuln:product>
      <vuln:product>cpe:/a:centericq:centericq:4.21</vuln:product>
      <vuln:product>cpe:/a:centericq:centericq:4.9.12</vuln:product>
      <vuln:product>cpe:/a:centericq:centericq:4.9.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0160</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-01T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T09:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31330" xml:lang="en">centericq-username-bo(31330)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0306" xml:lang="en">ADV-2007-0306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21932" xml:lang="en">21932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456255/100/0/threaded" xml:lang="en">20070107 TK53 Advisory #1: CenterICQ remote DoS buffer overflow in LiveJournal handling</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200701-20.xml" xml:lang="en">GLSA-200701-20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017545" xml:lang="en">1017545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2129" xml:lang="en">2129</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33408" xml:lang="en">33408</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the LiveJournal support (hooks/ljhook.cc) in CenterICQ 4.9.11 through 4.21.0, when using unofficial LiveJournal servers, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by adding the victim as a friend and using long (1) username and (2) real name strings.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0161">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:pml_driver_hpz12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:hp:color_laserjet_4650"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_4100"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_5100"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_5500"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_6100"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_7100"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_d"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_g"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_k"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_1100"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_1200"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_1210_all-in-one"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_1300"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_2100"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_2200"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_2400_photosmart_all-in-one"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_2500_photosmart_all-in-one"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_2510_photosmart"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_700"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_900"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:pml_driver_hpz12</vuln:product>
      <vuln:product>cpe:/h:hp:psc_2200</vuln:product>
      <vuln:product>cpe:/h:hp:psc_2100</vuln:product>
      <vuln:product>cpe:/h:hp:psc_2510_photosmart</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_k</vuln:product>
      <vuln:product>cpe:/h:hp:psc_900</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_d</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_4100</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_7100</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_6100</vuln:product>
      <vuln:product>cpe:/h:hp:psc_2400_photosmart_all-in-one</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_5500</vuln:product>
      <vuln:product>cpe:/h:hp:psc_1100</vuln:product>
      <vuln:product>cpe:/h:hp:psc_700</vuln:product>
      <vuln:product>cpe:/h:hp:psc_1300</vuln:product>
      <vuln:product>cpe:/h:hp:psc_1200</vuln:product>
      <vuln:product>cpe:/h:hp:psc_1210_all-in-one</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_g</vuln:product>
      <vuln:product>cpe:/h:hp:color_laserjet_4650</vuln:product>
      <vuln:product>cpe:/h:hp:psc_2500_photosmart_all-in-one</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_5100</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0161</vuln:cve-id>
    <vuln:discovered-datetime>2006-05-29T00:00:00.000-04:00</vuln:discovered-datetime>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:53.830-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T09:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0094" xml:lang="en">ADV-2007-0094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21935" xml:lang="en">21935</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456259/100/0/threaded" xml:lang="en">20070108 HP Multiple Products PML Driver Local Privilege Escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secway.org/advisory/AD20070108.txt" xml:lang="en">http://secway.org/advisory/AD20070108.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23663" xml:lang="en">23663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32654" xml:lang="en">32654</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31361" xml:lang="en">pml-driver-config-privilege-escalation(31361)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2128" xml:lang="en">2128</vuln:reference>
    </vuln:references>
    <vuln:summary>The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:unsanity:application_enhancer:2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:unsanity:application_enhancer:2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0162</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:04.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T09:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-08-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-08-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32661" xml:lang="en">32661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_8.20070109002959.18582.timor.html" xml:lang="en">http://landonf.bikemonkey.org/code/macosx/MOAB_Day_8.20070109002959.18582.timor.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31349" xml:lang="en">ape-appenhancer-privilege-escalation(31349)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21951" xml:lang="en">21951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23649" xml:lang="en">23649</vuln:reference>
    </vuln:references>
    <vuln:summary>Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and the (2) /Library/Frameworks/ApplicationEnhancer.framework directory, which allows local users to gain privileges by modifying or replacing the binary or library files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0163">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:securekit:securekit_steganography:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:securekit:securekit_steganography:1.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:securekit:securekit_steganography:1.8</vuln:product>
      <vuln:product>cpe:/a:securekit:securekit_steganography:1.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0163</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:04.420-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T09:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456283/100/0/threaded" xml:lang="en">20070106 Cracking Steganography Application in less than ONE minute</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23639" xml:lang="en">23639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31244" xml:lang="en">31244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://homepage.mac.com/adonismac/Advisory/steg/steganography.html" xml:lang="en">http://homepage.mac.com/adonismac/Advisory/steg/steganography.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31378" xml:lang="en">steganography-password-security-bypass(31378)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456519/100/0/threaded" xml:lang="en">20070107 A Major design Bug in Steganography 1.7.x, 1.8 (latest) (Updated Version)</vuln:reference>
    </vuln:references>
    <vuln:summary>SecureKit Steganography 1.7.1 and 1.8 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing the last 20 bytes of the JPEG image with alternate password information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0164">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:camouflage:camouflage:1.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:camouflage:camouflage:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0164</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:04.780-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T09:46:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21939" xml:lang="en">21939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23578" xml:lang="en">23578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32651" xml:lang="en">32651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html" xml:lang="en">http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31375" xml:lang="en">camouflage-password-security-bypass(31375)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456541/100/0/threaded" xml:lang="en">20070107 A Major design Bug in Camouflage 1.2.1 (latest)</vuln:reference>
    </vuln:references>
    <vuln:summary>Camouflage 1.2.1 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing certain bytes of the JPEG image with alternate password information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0165">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0165</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:54.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T09:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5920" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5920" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:2210" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2210" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102713-1" xml:lang="en">102713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0110" xml:lang="en">ADV-2007-0110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31576" xml:lang="en">31576</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31366" xml:lang="en">solaris-rpcbind-dos(31366)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21964" xml:lang="en">21964</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-036.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-036.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017492" xml:lang="en">1017492</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24056" xml:lang="en">24056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23700" xml:lang="en">23700</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:2210" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2210" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5920" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5920" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0166">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0166</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:05.280-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T09:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://security.freebsd.org/advisories/FreeBSD-SA-07:01.jail.asc" xml:lang="en">FreeBSD-SA-07:01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32726" xml:lang="en">32726</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22011" xml:lang="en">22011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017505" xml:lang="en">1017505</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23730" xml:lang="en">23730</vuln:reference>
    </vuln:references>
    <vuln:summary>The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0167">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ppc_search_engine:ppc_search_engine:1.61"/>
        <cpe-lang:fact-ref name="cpe:/a:wgs-ppc:wgs-ppc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ppc_search_engine:ppc_search_engine:1.61</vuln:product>
      <vuln:product>cpe:/a:wgs-ppc:wgs-ppc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0167</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:54.423-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-10T09:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21961" xml:lang="en">21961</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456386/100/0/threaded" xml:lang="en">20070109 ppc engine Multiple file inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001221.html" xml:lang="en">20070109 "ppc engine" is WGS-PPC</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31355" xml:lang="en">demoppc-inc-file-include(31355)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33454" xml:lang="en">33454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33453" xml:lang="en">33453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33452" xml:lang="en">33452</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33451" xml:lang="en">33451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33450" xml:lang="en">33450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33449" xml:lang="en">33449</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33448" xml:lang="en">33448</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33447" xml:lang="en">33447</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33446" xml:lang="en">33446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33445" xml:lang="en">33445</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33444" xml:lang="en">33444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2134" xml:lang="en">2134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3104" xml:lang="en">3104</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/; (5) admin.php and (6) index.php in admini/; (7) paypalipn/ipnprocess.php; (8) index.php and (9) registration.php in members/; and (10) ppcbannerclick.php and (11) ppcclick.php in main/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0168">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:9.01"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_enterprise_backup:10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:business_protection_suite:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:11.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:business_protection_suite:2.0</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_enterprise_backup:10.5</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:11.5</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:9.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0168</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:56.767-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T09:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/662400" xml:lang="en">VU#662400</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp" xml:lang="en">http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-002.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-002.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0154" xml:lang="en">ADV-2007-0154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31327" xml:lang="en">31327</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31442" xml:lang="en">brightstor-tapeengine-code-execution(31442)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22010" xml:lang="en">22010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456616/100/0/threaded" xml:lang="en">20070111 ZDI-07-002: CA BrightStor ARCserve Backup Tape Engine Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456711" xml:lang="en">20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456637" xml:lang="en">20070111 LS-20061002 - Computer Associates BrightStor ARCserve Backup Remote Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.lssec.com/advisories/LS-20061002.pdf" xml:lang="en">http://www.lssec.com/advisories/LS-20061002.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017506" xml:lang="en">1017506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23648" xml:lang="en">23648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://livesploit.com/advisories/LS-20061002.pdf" xml:lang="en">http://livesploit.com/advisories/LS-20061002.pdf</vuln:reference>
    </vuln:references>
    <vuln:summary>The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0169">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:9.01"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_enterprise_backup:10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:business_protection_suite:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:11.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:business_protection_suite:2.0</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_enterprise_backup:10.5</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:11.5</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:9.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0169</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T09:29:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/180336" xml:lang="en">VU#180336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/151032" xml:lang="en">VU#151032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp" xml:lang="en">http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31443" xml:lang="en">brightstor-messageengine-rpc-bo(31443)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31433" xml:lang="en">brightstor-tapeengine-rpc-bo(31433)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-004.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-004.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-003.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0154" xml:lang="en">ADV-2007-0154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22006" xml:lang="en">22006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22005" xml:lang="en">22005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456619/100/0/threaded" xml:lang="en">20070111 ZDI-07-003: CA BrightStor ARCserve Backup Message Engine Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456618/100/0/threaded" xml:lang="en">20070111 ZDI-07-004: CA BrightStor ARCserve Backup Tape Engine Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456711" xml:lang="en">20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017506" xml:lang="en">1017506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23648" xml:lang="en">23648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31327" xml:lang="en">31327</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=467" xml:lang="en">20070111 Computer Associates BrightStor ARCserve Backup RPC Engine PFC Request Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0170">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:allmyphp:allmyvisitors:0.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:allmyphp:allmyvisitors:0.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0170</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:56.953-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T08:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31316" xml:lang="en">allmyvisitors-index-file-include(31316)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21917" xml:lang="en">21917</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35904" xml:lang="en">35904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3097" xml:lang="en">3097</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the AMV_serverpath parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0171">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmylinks:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmylinks:0.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmylinks:0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmylinks:0.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmylinks:0.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmylinks:0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:voice_of_web:allmylinks:0.4</vuln:product>
      <vuln:product>cpe:/a:voice_of_web:allmylinks:0.5</vuln:product>
      <vuln:product>cpe:/a:voice_of_web:allmylinks:0.4.3</vuln:product>
      <vuln:product>cpe:/a:voice_of_web:allmylinks:0.4.1</vuln:product>
      <vuln:product>cpe:/a:voice_of_web:allmylinks:0.4.9</vuln:product>
      <vuln:product>cpe:/a:voice_of_web:allmylinks:0.4.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0171</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:57.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T10:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31314" xml:lang="en">allmylinks-index-file-include(31314)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21916" xml:lang="en">21916</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35909" xml:lang="en">35909</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3096" xml:lang="en">3096</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AML_opensite parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0172">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmyguests:0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:voice_of_web:allmyguests:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0172</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:57.110-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T10:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31310" xml:lang="en">allmyguests-multiple-file-include(31310)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21918" xml:lang="en">21918</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35923" xml:lang="en">35923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35921" xml:lang="en">35921</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35919" xml:lang="en">35919</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35917" xml:lang="en">35917</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35916" xml:lang="en">35916</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35915" xml:lang="en">35915</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3093" xml:lang="en">3093</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in unspecified parameters to (3) include/submit.inc.php, (4) admin/index.php, (5) include/cm_submit.inc.php, and (6) index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0173">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:l2j:statistik_script:0.09"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:l2j:statistik_script:0.09</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0173</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:57.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T10:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31309" xml:lang="en">l2j-statistik-index-file-include(31309)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0097" xml:lang="en">ADV-2007-0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21914" xml:lang="en">21914</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35914" xml:lang="en">35914</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3091" xml:lang="en">3091</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0174">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sina:sina:uc2006"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sina:sina:uc2006</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0174</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:57.297-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T10:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0093" xml:lang="en">ADV-2007-0093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secway.org/advisory/ad20070109EN.txt" xml:lang="en">http://secway.org/advisory/ad20070109EN.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23638" xml:lang="en">23638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32659" xml:lang="en">32659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116832852700467&amp;w=2" xml:lang="en">20070109 Sina UC ActiveX Multiple Remote Stack Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31350" xml:lang="en">sinauc-senddownloadfile-bo(31350)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31348" xml:lang="en">sinauc-sendchatroomopt-bo(31348)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21958" xml:lang="en">21958</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456378/100/0/threaded" xml:lang="en">20070109 Sina UC ActiveX Multiple Remote Stack Overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based multiple buffer overflows in the BRWOSSRE2UC.dll ActiveX Control in Sina UC2006 and earlier allow remote attackers to execute arbitrary code via a long string in the (1) astrVerion parameter to the SendChatRoomOpt function or (2) the astrDownDir parameter to the SendDownLoadFile function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:b2evolution:b2evolution:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:b2evolution:b2evolution:1.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:b2evolution:b2evolution:1.8.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:b2evolution:b2evolution:1.8.6</vuln:product>
      <vuln:product>cpe:/a:b2evolution:b2evolution:1.8.5</vuln:product>
      <vuln:product>cpe:/a:b2evolution:b2evolution:1.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0175</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:08.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T11:05:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31368" xml:lang="en">b2evolution-login-xss(31368)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21953" xml:lang="en">21953</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1568" xml:lang="en">DSA-1568</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30093" xml:lang="en">30093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23656" xml:lang="en">23656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32027" xml:lang="en">32027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=410568" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=410568</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gforge:gforge:4.5.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gforge:gforge:4.5.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0176</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:09.640-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T11:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21946" xml:lang="en">21946</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456296/100/0/threaded" xml:lang="en">20070108 GForge Cross Site Scripting vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.eazel.es/advisory006-gforge-cross-site-scripting-vulnerability.html" xml:lang="en">http://www.eazel.es/advisory006-gforge-cross-site-scripting-vulnerability.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017482" xml:lang="en">1017482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23675" xml:lang="en">23675</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31248" xml:lang="en">31248</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31346" xml:lang="en">gforge-words-xss(31346)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1475" xml:lang="en">DSA-1475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2133" xml:lang="en">2133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28598" xml:lang="en">28598</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0177">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.5_r14348"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.0:rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.5_r14348</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0177</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:57.563-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T11:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21956" xml:lang="en">21956</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES" xml:lang="en">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES" xml:lang="en">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES" xml:lang="en">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES" xml:lang="en">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/forum/forum.php?forum_id=652721" xml:lang="en">http://sourceforge.net/forum/forum.php?forum_id=652721</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0096" xml:lang="en">ADV-2007-0096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23647" xml:lang="en">23647</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31525" xml:lang="en">31525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31359" xml:lang="en">mediawiki-ajax-unspecified-xss(31359)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_6_sr.html" xml:lang="en">SUSE-SR:2007:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24889" xml:lang="en">24889</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0178">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php_web_scripts:easy_banner_pro:2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php_web_scripts:easy_banner_pro:2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0178</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:10.467-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T11:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456404/100/0/threaded" xml:lang="en">20070108 Easy Banner Pro Version 2.8 &lt;= Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33455" xml:lang="en">33455</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31374" xml:lang="en">easybannerpro-info-file-include(31374)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21967" xml:lang="en">21967</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2132" xml:lang="en">2132</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0179">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpkit:phpkit:1.6.1:rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpkit:phpkit:1.6.1:rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0179</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:11.063-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T12:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21962" xml:lang="en">21962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456384/100/0/threaded" xml:lang="en">20070109 Re: PHPKit 1.6.1 RC2 (faq/faq.php) Remote SQL Injection Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31266" xml:lang="en">31266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2131" xml:lang="en">2131</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0180">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ef_software:ef_commander:5.75"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ef_software:ef_commander:5.75</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0180</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:11.687-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T12:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://vuln.sg/efcommander575-en.html" xml:lang="en">http://vuln.sg/efcommander575-en.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23659" xml:lang="en">23659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32660" xml:lang="en">32660</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31365" xml:lang="en">efcommander-iso-pathname-bo(31365)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21969" xml:lang="en">21969</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in EF Commander 5.75 allows user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories, which produces a large filename that triggers the overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0181">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:scriptaty:magic_photo_storage_website"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scriptaty:magic_photo_storage_website</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0181</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:58.157-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T12:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0136" xml:lang="en">ADV-2007-0136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456264/100/0/threaded" xml:lang="en">20070108 magic photo storage website Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31347" xml:lang="en">magicphotostorage-config-file-include(31347)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21965" xml:lang="en">21965</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23687" xml:lang="en">23687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3100" xml:lang="en">3100</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0182">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:scriptaty:magic_photo_storage_website"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scriptaty:magic_photo_storage_website</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0182</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:17:13.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T10:07:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456389/100/0/threaded" xml:lang="en">20070108 magic photo storage website Multiple Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21965" xml:lang="en">21965</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33439" xml:lang="en">33439</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33438" xml:lang="en">33438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33437" xml:lang="en">33437</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33436" xml:lang="en">33436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33435" xml:lang="en">33435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33434" xml:lang="en">33434</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33433" xml:lang="en">33433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33432" xml:lang="en">33432</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33431" xml:lang="en">33431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33430" xml:lang="en">33430</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33429" xml:lang="en">33429</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33428" xml:lang="en">33428</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33427" xml:lang="en">33427</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33426" xml:lang="en">33426</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33425" xml:lang="en">33425</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33423" xml:lang="en">33423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33422" xml:lang="en">33422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33421" xml:lang="en">33421</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33420" xml:lang="en">33420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33419" xml:lang="en">33419</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33418" xml:lang="en">33418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33417" xml:lang="en">33417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33416" xml:lang="en">33416</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33415" xml:lang="en">33415</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33414" xml:lang="en">33414</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33413" xml:lang="en">33413</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33412" xml:lang="en">33412</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/33411" xml:lang="en">33411</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32668" xml:lang="en">32668</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2136" xml:lang="en">2136</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3) admin_email.php, (4) add_templates.php, (5) admin_paypal_email.php, (6) approve_member.php, (7) delete_member.php, (8) index.php, (9) list_members.php, (10) membership_pricing.php, or (11) send_email.php in admin/; (12) config.php or (13) db_config.php in include/; or (14) add_category.php, (15) add_news.php, (16) change_catalog_template.php, (17) couple_milestone.php, (18) couple_profile.php, (19) delete_category.php, (20) index.php, (21) login.php, (22) logout.php, (23) register.php, (24) upload_photo.php, (25) user_catelog_password.php, (26) user_email.php, (27) user_extend.php, or (28) user_membership_password.php in user/.  NOTE: the include/common_function.php vector is already covered by another candidate from the same date.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0183">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp1:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp10:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp2:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp3:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp4:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp5:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp6:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp7:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp8:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp9:enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp1</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp1:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp8</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp2</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp2:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp10</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp7:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp9:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp9</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp5:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp5</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp3</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp3:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp8:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp6</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp7</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp10:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp4:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp6:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0183</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:12.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T10:33:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21977" xml:lang="en">21977</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23605" xml:lang="en">23605</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32662" xml:lang="en">32662</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0184">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.0</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.0</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:0.7</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.3</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.2</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:0.8</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.1</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0184</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:58.423-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T13:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0095" xml:lang="en">ADV-2007-0095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21955" xml:lang="en">21955</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23641" xml:lang="en">23641</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32657" xml:lang="en">32657</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" xml:lang="en">SUSE-SR:2009:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://getahead.ltd.uk/dwr/changelog" xml:lang="en">http://getahead.ltd.uk/dwr/changelog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31377" xml:lang="en">dwr-include-exclude-security-bypass(31377)</vuln:reference>
    </vuln:references>
    <vuln:summary>Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to obtain unauthorized access to public methods via a crafted request that bypasses the include/exclude checks.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0185">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.0</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.0</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:0.7</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.3</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.2</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:0.8</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.1</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0185</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:58.500-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T13:34:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23641" xml:lang="en">23641</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0095" xml:lang="en">ADV-2007-0095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21955" xml:lang="en">21955</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32658" xml:lang="en">32658</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" xml:lang="en">SUSE-SR:2009:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://getahead.ltd.uk/dwr/changelog" xml:lang="en">http://getahead.ltd.uk/dwr/changelog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31382" xml:lang="en">dwr-servlet-engine-dos(31382)</vuln:reference>
    </vuln:references>
    <vuln:summary>Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to cause a denial of service (memory exhaustion and servlet outage) via unknown vectors related to a large number of calls in a batch.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0186">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass_4100"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:f5:firepass_4100</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0186</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:17:14.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T14:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://tech.f5.com/home/solutions/sol6920.html" xml:lang="en">https://tech.f5.com/home/solutions/sol6920.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://tech.f5.com/home/solutions/sol6919.html" xml:lang="en">https://tech.f5.com/home/solutions/sol6919.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21957" xml:lang="en">21957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.mnin.org/advisories/2007_firepass.pdf" xml:lang="en">http://www.mnin.org/advisories/2007_firepass.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23643" xml:lang="en">23643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23627" xml:lang="en">23627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" xml:lang="en">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32743" xml:lang="en">32743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32742" xml:lang="en">32742</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32741" xml:lang="en">32741</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32740" xml:lang="en">32740</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32739" xml:lang="en">32739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32738" xml:lang="en">32738</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32737" xml:lang="en">32737</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the xcho parameter to my.logon.php3; the (2) topblue, (3) midblue, (4) wtopblue, and certain other Custom color parameters in a per action to vdesk/admincon/index.php; the (5) h321, (6) h311, (7) h312, and certain other Front Door custom text color parameters in a per action to vdesk/admincon/index.php; the (8) ua parameter in a bro action to vdesk/admincon/index.php; the (9) app_param and (10) app_name parameters to webyfiers.php; (11) double eval functions; (12) JavaScript contained in an &lt;FP_DO_NOT_TOUCH> element; and (13) the vhost parameter to my.activation.php.  NOTE: it is possible that this candidate overlaps CVE-2006-3550.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0187">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.3"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.5"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.6"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.7"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.8"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.9"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:f5:firepass:5.5.1</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.4</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.3</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.5</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.7</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5.2</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.6</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.9</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.8</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.2</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:6.0</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0187</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:13.937-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T14:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://tech.f5.com/home/solutions/sol6924.html" xml:lang="en">https://tech.f5.com/home/solutions/sol6924.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21957" xml:lang="en">21957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.mnin.org/advisories/2007_firepass.pdf" xml:lang="en">http://www.mnin.org/advisories/2007_firepass.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/39167" xml:lang="en">39167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0141.html" xml:lang="en">20070105 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://tech.f5.com/home/solutions/sol6916.html" xml:lang="en">https://tech.f5.com/home/solutions/sol6916.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23640" xml:lang="en">23640</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23626" xml:lang="en">23626</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" xml:lang="en">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:summary>F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (3) Unicode encoding, (4) URL-encoded directory traversal or same-directory characters, or (5) upper case letters in the domain name.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0188">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.3"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.5"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.6"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.7"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.8"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.9"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:f5:firepass:5.5.1</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.4</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.3</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.5</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.7</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5.2</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.6</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.9</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.8</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.2</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:6.0</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0188</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:17:14.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T15:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://tech.f5.com/home/solutions/sol6922.html" xml:lang="en">https://tech.f5.com/home/solutions/sol6922.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21957" xml:lang="en">21957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.mnin.org/advisories/2007_firepass.pdf" xml:lang="en">http://www.mnin.org/advisories/2007_firepass.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32734" xml:lang="en">32734</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23640" xml:lang="en">23640</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" xml:lang="en">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:summary>F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP address ("dotless IP address"), which allows remote authenticated users to connect to the FirePass administrator console and certain other network resources.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0189">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:geobb:georgian_bulletin_board"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:geobb:georgian_bulletin_board</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0189</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:14.280-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T15:31:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31335" xml:lang="en">geobb-index-file-include(31335)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456251/100/0/threaded" xml:lang="en">20070107 GeoBB Georgian Bulletin Board Remote File Include Vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001230.html" xml:lang="en">20070110 Dispute of GeoBB RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33440" xml:lang="en">33440</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2141" xml:lang="en">2141</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  PHP remote file inclusion vulnerability in index.php in GeoBB Georgian Bulletin Board allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.  NOTE: CVE disputes this issue, since GeoBB 1.0 sets $action to a whitelisted value.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0190">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:edit-x:ecommerce"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:edit-x:ecommerce</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0190</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:59.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T15:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0158" xml:lang="en">ADV-2007-0158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456439/100/0/threaded" xml:lang="en">20070109 edit-x ecommerce (include_dir) Remote File include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31384" xml:lang="en">editx-editaddress-file-include(31384)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21974" xml:lang="en">21974</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2139" xml:lang="en">2139</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0191">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mkportal:mkportal"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mkportal:mkportal</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0191</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:14.670-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T15:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31304" xml:lang="en">mkportal-admin-xss(31304)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456042/100/100/threaded" xml:lang="en">20070105 MkPortal Admin XSS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33399" xml:lang="en">33399</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2138" xml:lang="en">2138</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in admin.php in MKPortal allows remote attackers to inject arbitrary web script or HTML via two certain fields in a contents_new operation in the ad_contents section.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0192">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mkportal:mkportal"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mkportal:mkportal</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0192</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:14.890-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T15:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/455894/100/100/threaded" xml:lang="en">20070104 MkPortal "All Guests are Admin" Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33400" xml:lang="en">33400</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2137" xml:lang="en">2137</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as demonstrated using a getURL of admin.php within a .swf file contained in an IFRAME element, aka the "All Guests are Admin" attack.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0193">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fon:la_fonera"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fon:la_fonera</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0193</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:15.093-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T15:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456344/100/0/threaded" xml:lang="en">20070107 Re: FON Router allows anonymous web access</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456128/100/0/threaded" xml:lang="en">20070106 FON Router allows anonymous web access</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33441" xml:lang="en">33441</vuln:reference>
    </vuln:references>
    <vuln:summary>FON La Fonera routers do not properly limit DNS service access by unauthenticated clients, which allows remote attackers to tunnel traffic via DNS requests for hosts that should not be accessible before authentication.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0194">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mkportal:mkportal:1.1_rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mkportal:mkportal:1.1_rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0194</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:15.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T15:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456257/100/0/threaded" xml:lang="en">20070108 MKPortal Full Path Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/33407" xml:lang="en">33407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31333" xml:lang="en">mkportal-admin-path-disclosure(31333)</vuln:reference>
    </vuln:references>
    <vuln:summary>admin.php in MKPortal M1.1 RC1 allows remote attackers to obtain sensitive information via a direct request with an MK_PATH=1 query string, which reveals the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0195">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.3"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.5"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.6"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.7"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.8"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.9"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:f5:firepass:5.5.1</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.4</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.9</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.8</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.3</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.5</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.2</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.7</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:6.0</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.6</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0195</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:17:15.480-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T15:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://tech.f5.com/home/solutions/sol6923.html" xml:lang="en">https://tech.f5.com/home/solutions/sol6923.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21957" xml:lang="en">21957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.mnin.org/advisories/2007_firepass.pdf" xml:lang="en">http://www.mnin.org/advisories/2007_firepass.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32736" xml:lang="en">32736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23627" xml:lang="en">23627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" xml:lang="en">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:summary>my.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to confirm the validity of an LDAP account.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0196">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:motionborg:motionborg_web_real_estate:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:motionborg:motionborg_web_real_estate:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0196</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-08T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T12:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31360" xml:lang="en">motionborg-admincheckuser-sql-injection(31360)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0143" xml:lang="en">ADV-2007-0143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21963" xml:lang="en">21963</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23531" xml:lang="en">23531</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32718" xml:lang="en">32718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3105" xml:lang="en">3105</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters.  NOTE: some details were obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0197">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0197</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:59.797-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T12:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-399"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-047A.html" xml:lang="en">TA07-047A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/240880" xml:lang="en">VU#240880</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31410" xml:lang="en">macos-finder-dos(31410)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0140" xml:lang="en">ADV-2007-0140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017662" xml:lang="en">1017662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21980" xml:lang="en">21980</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456578/100/0/threaded" xml:lang="en">20070111 DMA[2007-0107a] OmniWeb Javascript Alert Format String Vulnerabiity and DMA[2007-0109a] Apple Finder Disk Image Volume Label Overflow / DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/32714" xml:lang="en">32714</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalmunition.com/DMA%5B2007-0109a%5D.txt" xml:lang="en">http://www.digitalmunition.com/DMA%5B2007-0109a%5D.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24198" xml:lang="en">24198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-09-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-09-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" xml:lang="en">APPLE-SA-2007-02-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305102" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305102</vuln:reference>
    </vuln:references>
    <vuln:summary>Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0198">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:ip_contact_center_enterprise:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:ip_contact_center_hosted:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_contact_center_enterprise:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_contact_center_hosted:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:ip_contact_center_enterprise:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:ip_contact_center_hosted:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_contact_center_enterprise:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_contact_center_hosted:7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:unified_contact_center_hosted:7.1</vuln:product>
      <vuln:product>cpe:/a:cisco:ip_contact_center_hosted:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:ip_contact_center_hosted:7.1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_contact_center_enterprise:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_contact_center_enterprise:7.1</vuln:product>
      <vuln:product>cpe:/a:cisco:ip_contact_center_enterprise:7.1</vuln:product>
      <vuln:product>cpe:/a:cisco:ip_contact_center_enterprise:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_contact_center_hosted:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0198</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:59.893-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T13:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070110-jtapi.shtml" xml:lang="en">20070110 Cisco Unified Contact Center and IP Contact Center JTapi Gateway Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0138" xml:lang="en">ADV-2007-0138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21988" xml:lang="en">21988</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32682" xml:lang="en">32682</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017499" xml:lang="en">1017499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23710" xml:lang="en">23710</vuln:reference>
    </vuln:references>
    <vuln:summary>The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart) via a certain TCP session on the JTapi server port.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0199">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0199</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:59.987-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T13:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5714" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5714" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070110-dlsw.shtml" xml:lang="en">20070110 DLSw Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0139" xml:lang="en">ADV-2007-0139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32683" xml:lang="en">32683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21990" xml:lang="en">21990</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017498" xml:lang="en">1017498</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23697" xml:lang="en">23697</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5714" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5714" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0200">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:geoffrey_golliher:axiom_photo_news_gallery:0.8.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:geoffrey_golliher:axiom_photo_news_gallery:0.8.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0200</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:00.047-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T13:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0107" xml:lang="en">ADV-2007-0107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001233.html" xml:lang="en">20070110 source verify - Axiom RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32716" xml:lang="en">32716</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31372" xml:lang="en">axiom-template-file-include(31372)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21972" xml:lang="en">21972</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23715" xml:lang="en">23715</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3108" xml:lang="en">3108</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to execute arbitrary PHP code via a URL in the baseAxiomPath parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0201">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tis:internet_firewall_toolkit:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tis:internet_firewall_toolkit:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0201</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:17.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T13:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31363" xml:lang="en">tisfwtk-ftpgw-bo(31363)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21960" xml:lang="en">21960</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ranum.com/security/computer_security/editorials/codetools/" xml:lang="en">http://www.ranum.com/security/computer_security/editorials/codetools/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017481" xml:lang="en">1017481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35967" xml:lang="en">35967</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the cmd_usr function in ftp-gw in TIS Internet Firewall Toolkit (FWTK) allows remote attackers to execute arbitrary code via a long destination hostname (dest).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0202">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:4.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:4.0.1</vuln:product>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:3.13</vuln:product>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:4.0.2</vuln:product>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:3.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0202</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:00.283-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T13:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31393" xml:lang="en">@lexguestbook-index-sql-injection(31393)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0137" xml:lang="en">ADV-2007-0137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21926" xml:lang="en">21926</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456218/100/0/threaded" xml:lang="en">20070107 @lex Guestbook &lt;= 4.0.2 Remote Command Execution Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23637" xml:lang="en">23637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31707" xml:lang="en">31707</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/20070107.txt" xml:lang="en">http://acid-root.new.fr/poc/20070107.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2135" xml:lang="en">2135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3103" xml:lang="en">3103</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0203">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.9.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.9.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0203</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:00.393-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T13:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0" xml:lang="en">http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23702" xml:lang="en">23702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0125" xml:lang="en">ADV-2007-0125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32666" xml:lang="en">32666</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21987" xml:lang="en">21987</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" xml:lang="en">MDKSA-2007:199</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0204">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.9.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.9.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0204</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:00.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-11T13:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/23702" xml:lang="en">23702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0125" xml:lang="en">ADV-2007-0125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0" xml:lang="en">http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32667" xml:lang="en">32667</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31387" xml:lang="en">phpmyadmin-unspecified-xss(31387)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21987" xml:lang="en">21987</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" xml:lang="en">MDKSA-2007:199</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.9.2-rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0205">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:4.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:4.0.1</vuln:product>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:3.13</vuln:product>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:4.0.2</vuln:product>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:3.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0205</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:00.563-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T09:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/31397" xml:lang="en">@lexguestbook-livreinclude-file-include(31397)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21926" xml:lang="en">21926</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456218/100/0/threaded" xml:lang="en">20070107 @lex Guestbook &lt;= 4.0.2 Remote Command Execution Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2135" xml:lang="en">2135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31709" xml:lang="en">31709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/31708" xml:lang="en">31708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/3103" xml:lang="en">3103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/20070107.txt" xml:lang="en">http://acid-root.new.fr/poc/20070107.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters.  NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0206">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2::hp_ux_10.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2::hp_ux_11.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2::nt_4.x_windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4::hp_ux_11.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4::nt_4.x_windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.41"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.41::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.0.1::hp_ux_11.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.0.1::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.0.1::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.0.1::windows_2000_xp"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.50"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.50::hp_ux_11.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.50::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.50::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.50::windows_2000_xp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2::hp_ux_10.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.41::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.50::linux</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2::hp_ux_11.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.0.1</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.0.1::windows_2000_xp</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.0.1::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.50</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4::hp_ux_11.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.50::windows_2000_xp</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4::nt_4.x_windows_2000</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.50::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.0.1::hp_ux_11.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.0.1::linux</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.50::hp_ux_11.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.41</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2::nt_4.x_windows_2000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0206</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:00.643-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T09:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0153" xml:lang="en">ADV-2007-0153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22009" xml:lang="en">22009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456615/100/0/threaded" xml:lang="en">SSRT061174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/456615/100/0/threaded" xml:lang="en">HPSBMA02175</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/32729" xml:lang="en">32729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017503" xml:lang="en">1017503</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2140" xml:lang="en">2140</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to read arbitrary files via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0208">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2006"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:word_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2006</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0208</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-14T11:46:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:700" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:700" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-014.mspx" xml:lang="en">MS07-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0583" xml:lang="en">ADV-2007-0583</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017639" xml:lang="en">1017639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22477" xml:lang="en">22477</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/34385" xml:lang="en">34385</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:700" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:700" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0209">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2006"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2006</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0209</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-14T12:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:187" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:187" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0583" xml:lang="en">ADV-2007-0583</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017639" xml:lang="en">1017639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22482" xml:lang="en">22482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-014.mspx" xml:lang="en">MS07-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/34386" xml:lang="en">34386</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:187" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:187" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0210">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0210</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:00.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-13T20:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:186" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:186" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-007.mspx" xml:lang="en">MS07-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0576" xml:lang="en">ADV-2007-0576</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017634" xml:lang="en">1017634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22499" xml:lang="en">22499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31889" xml:lang="en">31889</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24132" xml:lang="en">24132</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:186" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:186" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Window Image Acquisition (WIA) Service in Microsoft Windows XP SP2 allows local users to gain privileges via unspecified vectors involving an "unchecked buffer," probably a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0211">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0211</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:01.033-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-13T21:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:224" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:224" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/240796" xml:lang="en">VU#240796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-006.mspx" xml:lang="en">MS07-006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0575" xml:lang="en">ADV-2007-0575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017633" xml:lang="en">1017633</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22481" xml:lang="en">22481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31890" xml:lang="en">31890</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24126" xml:lang="en">24126</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:224" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:224" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0213">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2007"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0213</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:01.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-05-09T11:25:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1890" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1890" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/343145" xml:lang="en">VU#343145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx" xml:lang="en">MS07-026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1711" xml:lang="en">ADV-2007-1711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" xml:lang="en">SSRT071422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/33889" xml:lang="en">exchange-mime-base64-code-execution(33889)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018015" xml:lang="en">1018015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23809" xml:lang="en">23809</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/34391" xml:lang="en">34391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25183" xml:lang="en">25183</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1890" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1890" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0214">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0214</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:01.220-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-13T21:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:125" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:125" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/563756" xml:lang="en">VU#563756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-008.mspx" xml:lang="en">MS07-008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0577" xml:lang="en">ADV-2007-0577</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017635" xml:lang="en">1017635</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22478" xml:lang="en">22478</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31884" xml:lang="en">31884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24136" xml:lang="en">24136</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:125" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:125" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0215">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0215</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:01.313-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-05-09T10:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1971" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1971" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-026.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-026.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx" xml:lang="en">MS07-023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1708" xml:lang="en">ADV-2007-1708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" xml:lang="en">SSRT071422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/33913" xml:lang="en">excel-biff-file-bo(33913)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018012" xml:lang="en">1018012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23760" xml:lang="en">23760</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" xml:lang="en">SSRT071422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/467988/100/0/threaded" xml:lang="en">20070508 ZDI-07-026: Microsoft Excel BIFF File Format Named Graph Record Parsing Stack Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/34393" xml:lang="en">34393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25150" xml:lang="en">25150</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1971" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1971" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0216">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:works:8.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0216</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-13T10:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5309" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5309" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx" xml:lang="en">MS08-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0513/references" xml:lang="en">ADV-2008-0513</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019386" xml:lang="en">1019386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27657" xml:lang="en">27657</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28904" xml:lang="en">28904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">HPSBST02314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=659" xml:lang="en">20080208 Microsoft Office Works Converter Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5309" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5309" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0217">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:sp4"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.01:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0217</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:01.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-14T13:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1141" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1141" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/613564" xml:lang="en">VU#613564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-016.mspx" xml:lang="en">MS07-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0584" xml:lang="en">ADV-2007-0584</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017642" xml:lang="en">1017642</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22489" xml:lang="en">22489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31892" xml:lang="en">31892</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24156" xml:lang="en">24156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=473" xml:lang="en">20070213 Microsoft 'wininet.dll' FTP Reply Null Termination Heap Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/462303/100/0/threaded" xml:lang="en">20070309 MS07-016 FTP Response DOS PoC</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1141" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1141" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0218">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:sp4"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::itanium"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.01:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0218</vuln:cve-id>
    <vuln:published-datetime>2007-06-12T15:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:27:22.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-06-13T11:33:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:1084" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1084" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-163A.html" xml:lang="en">TA07-163A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx" xml:lang="en">MS07-033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/32106" xml:lang="en">webbrowser-object-code-execution(32106)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2153" xml:lang="en">ADV-2007-2153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24372" xml:lang="en">24372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" xml:lang="en">HPSBST02231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" xml:lang="en">HPSBST02231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1018235" xml:lang="en">1018235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/25627" xml:lang="en">25627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/35348" xml:lang="en">35348</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=542" xml:lang="en">20070612 Microsoft License Manager and urlmon.dll COM Object Interaction Invalid Memory Access Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:1084" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:1084" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0219">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:sp4"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.01:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0219</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:01.703-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-14T13:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:257" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:257" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/771788" xml:lang="en">VU#771788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS07-016.mspx" xml:lang="en">MS07-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/32427" xml:lang="en">ie-com-activex-code-execution(32427)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0584" xml:lang="en">ADV-2007-0584</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017643" xml:lang="en">1017643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22504" xml:lang="en">22504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31895" xml:lang="en">31895</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31894" xml:lang="en">31894</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/31893" xml:lang="en">31893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/24156" xml:lang="en">24156</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:257" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:257" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a diffe