<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" nvd_xml_version="2.0" pub_date="2013-05-25T06:40:42" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
  <entry id="CVE-2008-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.61"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.62"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.52"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.51"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.50"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.49"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.48"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.47"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.46"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.45"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.60"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.59"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.58"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.57"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.56"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.55"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.54"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.53"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31:-rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31:-rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31:-rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31:-rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31:-rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31:-rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.52</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.47</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31:-rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.53</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.61</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.62</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.46</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.50</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.54</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31:-rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.42</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.56</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.55</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.44</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.59</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.51</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.57</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31:-rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.58</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.45</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31:-rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.49</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.43</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.48</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.60</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0001</vuln:cve-id>
    <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-15T15:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9709" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9709" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27280" xml:lang="en">27280</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00828.html" xml:lang="en">FEDORA-2008-0748</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-2146" xml:lang="en">https://issues.rpath.com/browse/RPL-2146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39672" xml:lang="en">linux-directory-security-bypass(39672)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0151" xml:lang="en">ADV-2008-0151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-578-1" xml:lang="en">USN-578-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-574-1" xml:lang="en">USN-574-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/486485/100/0/threaded" xml:lang="en">20080117 rPSA-2008-0021-1 kernel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0089.html" xml:lang="en">RHSA-2008:0089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:112" xml:lang="en">MDVSA-2008:112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:044" xml:lang="en">MDVSA-2008:044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.14" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1479" xml:lang="en">DSA-1479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0021" xml:lang="en">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019289" xml:lang="en">1019289</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29245" xml:lang="en">29245</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28971" xml:lang="en">28971</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28806" xml:lang="en">28806</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28748" xml:lang="en">28748</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28706" xml:lang="en">28706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28664" xml:lang="en">28664</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28643" xml:lang="en">28643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28628" xml:lang="en">28628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28626" xml:lang="en">28626</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28558" xml:lang="en">28558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28485" xml:lang="en">28485</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2008-0055.html" xml:lang="en">RHSA-2008:0055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00002.html" xml:lang="en">SUSE-SA:2008:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html" xml:lang="en">SUSE-SA:2008:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.16" xml:lang="en">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=974a9f0b47da74e28f68b9c8645c3786aa5ace1a" xml:lang="en">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=974a9f0b47da74e28f68b9c8645c3786aa5ace1a</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9709" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9709" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:6.0.11</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.7</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.9</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.6</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.14</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.8</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.10</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.15</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.12</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0002</vuln:cve-id>
    <vuln:published-datetime>2008-02-11T20:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:45.220-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T10:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00460.html" xml:lang="en">FEDORA-2008-1603</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00315.html" xml:lang="en">FEDORA-2008-1467</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/3316" xml:lang="en">ADV-2009-3316</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2780" xml:lang="en">ADV-2008-2780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0488" xml:lang="en">ADV-2008-0488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/31681" xml:lang="en">31681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27703" xml:lang="en">27703</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" xml:lang="en">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487812/100/0/threaded" xml:lang="en">20080208 CVE-2008-0002: Tomcat information disclosure vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/security-6.html" xml:lang="en">http://tomcat.apache.org/security-6.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3216" xml:lang="en">http://support.apple.com/kb/HT3216</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3638" xml:lang="en">3638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200804-10.xml" xml:lang="en">GLSA-200804-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/37460" xml:lang="en">37460</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32222" xml:lang="en">32222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29711" xml:lang="en">29711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28915" xml:lang="en">28915</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28834" xml:lang="en">28834</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" xml:lang="en">SUSE-SR:2009:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html" xml:lang="en">APPLE-SA-2008-10-09</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::as"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::es"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::ws"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.5.z::as"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.5.z::es"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:5.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:openpegasus:management_server:2.6.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openpegasus:management_server:2.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0003</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T15:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T13:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10282" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10282" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27188" xml:lang="en">27188</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0002.html" xml:lang="en">RHSA-2008:0002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00480.html" xml:lang="en">FEDORA-2008-0572</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00424.html" xml:lang="en">FEDORA-2008-0506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=426578" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=426578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39527" xml:lang="en">openpegasus-pambasic-bo(39527)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4129" xml:lang="en">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4129</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1391/references" xml:lang="en">ADV-2008-1391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1234/references" xml:lang="en">ADV-2008-1234</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0638" xml:lang="en">ADV-2008-0638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0063" xml:lang="en">ADV-2008-0063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27172" xml:lang="en">27172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/490917/100/0/threaded" xml:lang="en">20080416 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2008-January/001879.html" xml:lang="en">20080115 vuldb confusion between OpenPegasus issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019159" xml:lang="en">1019159</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29986" xml:lang="en">29986</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29785" xml:lang="en">29785</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29056" xml:lang="en">29056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28462" xml:lang="en">28462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28338" xml:lang="en">28338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/40082" xml:lang="en">40082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.vmware.com/pipermail/security-announce/2008/000014.html" xml:lang="en">[Security-announce] 20080415 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01438409" xml:lang="en">SSRT080000</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01438409" xml:lang="en">HPSBMA02331</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10282" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10282" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to use PAM and without PEGASUS_USE_PAM_STANDALONE_PROC defined, might allow remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2007-5360.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0004">
    <vuln:cve-id>CVE-2008-0004</vuln:cve-id>
    <vuln:published-datetime>2009-03-26T06:12:08.780-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-26T06:12:09.313-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0005</vuln:cve-id>
    <vuln:published-datetime>2008-01-11T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-06T22:41:45.753-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-14T09:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10812" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10812" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html" xml:lang="en">FEDORA-2008-1695</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html" xml:lang="en">FEDORA-2008-1711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39615" xml:lang="en">apache-modproxyftp-utf7-xss(39615)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1875/references" xml:lang="en">ADV-2008-1875</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-575-1" xml:lang="en">USN-575-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019185" xml:lang="en">1019185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27234" xml:lang="en">27234</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/505990/100/0/threaded" xml:lang="en">20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/486167/100/0/threaded" xml:lang="en">20080110 SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0009.html" xml:lang="en">RHSA-2008:0009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0008.html" xml:lang="en">RHSA-2008:0008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0007.html" xml:lang="en">RHSA-2008:0007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0006.html" xml:lang="en">RHSA-2008:0006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0005.html" xml:lang="en">RHSA-2008:0005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0004.html" xml:lang="en">RHSA-2008:0004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:016" xml:lang="en">MDVSA-2008:016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:015" xml:lang="en">MDVSA-2008:015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:014" xml:lang="en">MDVSA-2008:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3526" xml:lang="en">3526</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASONRES</vuln:source>
      <vuln:reference href="http://securityreason.com/achievement_securityalert/49" xml:lang="en">20080110 Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200803-19.xml" xml:lang="en">GLSA-200803-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35650" xml:lang="en">35650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30732" xml:lang="en">30732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29640" xml:lang="en">29640</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29348" xml:lang="en">29348</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28977" xml:lang="en">28977</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28749" xml:lang="en">28749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28607" xml:lang="en">28607</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28526" xml:lang="en">28526</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28471" xml:lang="en">28471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28467" xml:lang="en">28467</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" xml:lang="en">SSRT090208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" xml:lang="en">HPSBOV02683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2" xml:lang="en">HPSBUX02465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2" xml:lang="en">HPSBUX02465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2" xml:lang="en">HPSBUX02431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2" xml:lang="en">HPSBUX02431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.vmware.com/pipermail/security-announce/2009/000062.html" xml:lang="en">[security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html" xml:lang="en">SUSE-SA:2008:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10812" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10812" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:solaris_libfont"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:solaris_libxfont"/>
        <cpe-lang:fact-ref name="cpe:/a:x.org:xserver:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:solaris_libxfont</vuln:product>
      <vuln:product>cpe:/a:x.org:xserver:1.4</vuln:product>
      <vuln:product>cpe:/a:sun:solaris_libfont</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0006</vuln:cve-id>
    <vuln:published-datetime>2008-01-18T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:45.643-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-21T09:13:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10021" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10021" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27336" xml:lang="en">27336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103192-1" xml:lang="en">103192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.freedesktop.org/archives/xorg/2008-January/031918.html" xml:lang="en">[xorg] 20080117 X.Org security advisory: multiple vulnerabilities in the X server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00771.html" xml:lang="en">FEDORA-2008-0891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00704.html" xml:lang="en">FEDORA-2008-0831</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00674.html" xml:lang="en">FEDORA-2008-0794</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00641.html" xml:lang="en">FEDORA-2008-0760</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=428044" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=428044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39767" xml:lang="en">xorg-pcffont-bo(39767)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3000" xml:lang="en">ADV-2008-3000</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0703" xml:lang="en">ADV-2008-0703</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0497/references" xml:lang="en">ADV-2008-0497</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0184" xml:lang="en">ADV-2008-0184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0179" xml:lang="en">ADV-2008-0179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-571-1" xml:lang="en">USN-571-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27352" xml:lang="en">27352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0064.html" xml:lang="en">RHSA-2008:0064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0030.html" xml:lang="en">RHSA-2008:0030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0029.html" xml:lang="en">RHSA-2008:0029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:024" xml:lang="en">MDVSA-2008:024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:022" xml:lang="en">MDVSA-2008:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:021" xml:lang="en">MDVSA-2008:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2008-038.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2008-038.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019232" xml:lang="en">1019232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200801-09.xml" xml:lang="en">GLSA-200801-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32545" xml:lang="en">32545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28621" xml:lang="en">28621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28592" xml:lang="en">28592</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28571" xml:lang="en">28571</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28550" xml:lang="en">28550</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28544" xml:lang="en">28544</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28542" xml:lang="en">28542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28540" xml:lang="en">28540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28536" xml:lang="en">28536</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28535" xml:lang="en">28535</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28532" xml:lang="en">28532</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28500" xml:lang="en">28500</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28273" xml:lang="en">28273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.html" xml:lang="en">SUSE-SA:2008:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVNDB</vuln:source>
      <vuln:reference href="http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001043.html" xml:lang="en">JVNDB-2008-001043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN88935101/index.html" xml:lang="en">JVN#88935101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321" xml:lang="en">HPSBUX02381</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321" xml:lang="en">HPSBUX02381</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=204362" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=204362</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-2010" xml:lang="en">https://issues.rpath.com/browse/RPL-2010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&amp;heading=AIX61&amp;path=/200802/SECURITY/20080227/datafile112539&amp;label=AIX%20X%20server%20multiple%20vulnerabilities" xml:lang="en">http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&amp;heading=AIX61&amp;path=/200802/SECURITY/20080227/datafile112539&amp;label=AIX%20X%20server%20multiple%20vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487335/100/0/threaded" xml:lang="en">20080130 rPSA-2008-0032-1 xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata42.html#006_xorg" xml:lang="en">[4.2] 20080208 006: SECURITY FIX: February 8, 2008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata41.html#012_xorg" xml:lang="en">[4.1] 20080208 012: SECURITY FIX: February 8, 2008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml" xml:lang="en">GLSA-200805-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2008-077.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2008-077.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-201230-1" xml:lang="en">201230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200804-05.xml" xml:lang="en">GLSA-200804-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30161" xml:lang="en">30161</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29707" xml:lang="en">29707</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29622" xml:lang="en">29622</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29139" xml:lang="en">29139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28941" xml:lang="en">28941</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28885" xml:lang="en">28885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28843" xml:lang="en">28843</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28718" xml:lang="en">28718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html" xml:lang="en">SUSE-SR:2008:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10021" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10021" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0007</vuln:cve-id>
    <vuln:published-datetime>2008-02-07T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:45.783-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-08T13:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9412" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9412" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2222/references" xml:lang="en">ADV-2008-2222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0445/references" xml:lang="en">ADV-2008-0445</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-618-1" xml:lang="en">USN-618-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0787.html" xml:lang="en">RHSA-2008:0787</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:174" xml:lang="en">MDVSA-2008:174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:112" xml:lang="en">MDVSA-2008:112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.17" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1565" xml:lang="en">DSA-1565</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33280" xml:lang="en">33280</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31246" xml:lang="en">31246</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30769" xml:lang="en">30769</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30116" xml:lang="en">30116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30112" xml:lang="en">30112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30110" xml:lang="en">30110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30018" xml:lang="en">30018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lkml.org/lkml/2008/2/6/457" xml:lang="en">[linux-kernel] 20080206 [patch 60/73] vm audit: add VM_DONTEXPAND to mmap for drivers that need it (CVE-2008-0007)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.vmware.com/pipermail/security-announce/2008/000023.html" xml:lang="en">[Security-announce] 20080728 VMSA-2008-00011 Updated ESX service console packages for Samba and vmnix</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html" xml:lang="en">SUSE-SA:2008:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27705" xml:lang="en">27705</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27686" xml:lang="en">27686</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487808/100/0/threaded" xml:lang="en">20080208 rPSA-2008-0048-1 kernel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0237.html" xml:lang="en">RHSA-2008:0237</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0233.html" xml:lang="en">RHSA-2008:0233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0211.html" xml:lang="en">RHSA-2008:0211</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:072" xml:lang="en">MDVSA-2008:072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:044" xml:lang="en">MDVSA-2008:044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1504" xml:lang="en">DSA-1504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1503" xml:lang="en">DSA-1503</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0048" xml:lang="en">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019357" xml:lang="en">1019357</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29570" xml:lang="en">29570</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29058" xml:lang="en">29058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28826" xml:lang="en">28826</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28806" xml:lang="en">28806</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00007.html" xml:lang="en">SUSE-SA:2008:017</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9412" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9412" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:2007.1"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:2007.1::x86-64"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:2008.0"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:fedora:7"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:fedora:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:pulseaudio:pulseaudio:0.9.6"/>
          <cpe-lang:fact-ref name="cpe:/a:pulseaudio:pulseaudio:0.9.8"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pulseaudio:pulseaudio:0.9.8</vuln:product>
      <vuln:product>cpe:/a:pulseaudio:pulseaudio:0.9.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0008</vuln:cve-id>
    <vuln:published-datetime>2008-01-28T19:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-29T12:18:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00869.html" xml:lang="en">FEDORA-2008-0994</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00852.html" xml:lang="en">FEDORA-2008-0963</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=425481" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=425481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.novell.com/show_bug.cgi?id=347822" xml:lang="en">https://bugzilla.novell.com/show_bug.cgi?id=347822</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39992" xml:lang="en">pulseaudio-padroproot-privilege-escalation(39992)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0283" xml:lang="en">ADV-2008-0283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-573-1" xml:lang="en">USN-573-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27449" xml:lang="en">27449</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:027" xml:lang="en">MDVSA-2008:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1476" xml:lang="en">DSA-1476</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200802-07.xml" xml:lang="en">GLSA-200802-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28952" xml:lang="en">28952</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28738" xml:lang="en">28738</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28623" xml:lang="en">28623</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28608" xml:lang="en">28608</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://pulseaudio.org/changeset/2100" xml:lang="en">http://pulseaudio.org/changeset/2100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=207214" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=207214</vuln:reference>
    </vuln:references>
    <vuln:summary>The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0009</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T16:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:46.203-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T17:31:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=431206" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=431206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0487/references" xml:lang="en">ADV-2008-0487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt" xml:lang="en">http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00255.html" xml:lang="en">FEDORA-2008-1423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00254.html" xml:lang="en">FEDORA-2008-1422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27799" xml:lang="en">27799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27704" xml:lang="en">27704</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487982/100/0/threaded" xml:lang="en">20080212 CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28896" xml:lang="en">28896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28835" xml:lang="en">28835</vuln:reference>
    </vuln:references>
    <vuln:summary>The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0010</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T16:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:46.283-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T17:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0487/references" xml:lang="en">ADV-2008-0487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/5093" xml:lang="en">5093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt" xml:lang="en">http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00255.html" xml:lang="en">FEDORA-2008-1423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00254.html" xml:lang="en">FEDORA-2008-1422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27796" xml:lang="en">27796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27704" xml:lang="en">27704</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487982/100/0/threaded" xml:lang="en">20080212 CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1494" xml:lang="en">DSA-1494</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28896" xml:lang="en">28896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28875" xml:lang="en">28875</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28835" xml:lang="en">28835</vuln:reference>
    </vuln:references>
    <vuln:summary>The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:8.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:xp:sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:9.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:2008::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:2008::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:2008::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:vista:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:vista:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:10.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:directx:10.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:9.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:7.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0011</vuln:cve-id>
    <vuln:published-datetime>2008-06-11T22:32:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:46.377-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-06-12T09:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5236" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5236" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-162B.html" xml:lang="en">TA08-162B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/29581" xml:lang="en">29581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-033.mspx" xml:lang="en">MS08-033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1020222" xml:lang="en">1020222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30579" xml:lang="en">30579</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1780" xml:lang="en">ADV-2008-1780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121380194923597&amp;w=2" xml:lang="en">SSRT080087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121380194923597&amp;w=2" xml:lang="en">SSRT080087</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5236" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5236" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.58</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0012</vuln:cve-id>
    <vuln:published-datetime>2008-11-17T18:30:00.377-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:50:03.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-11-18T11:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/768681" xml:lang="en">VU#768681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39918" xml:lang="en">application-rpc-config1-bo(39918)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3127" xml:lang="en">ADV-2008-3127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/32261" xml:lang="en">32261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/310.html" xml:lang="en">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32618" xml:lang="en">32618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.iss.net/archive/trend.html" xml:lang="en">http://blogs.iss.net/archive/trend.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-2008-0013 and CVE-2008-0014.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.58</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0013</vuln:cve-id>
    <vuln:published-datetime>2008-11-17T18:30:00.407-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:50:04.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-11-18T11:29:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/768681" xml:lang="en">VU#768681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39919" xml:lang="en">application-rpc-config2-bo(39919)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3127" xml:lang="en">ADV-2008-3127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/32261" xml:lang="en">32261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/310.html" xml:lang="en">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32618" xml:lang="en">32618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.iss.net/archive/trend.html" xml:lang="en">http://blogs.iss.net/archive/trend.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-2008-0012 and CVE-2008-0014.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.58</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0014</vuln:cve-id>
    <vuln:published-datetime>2008-11-17T18:30:00.420-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:50:04.310-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-11-18T11:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/768681" xml:lang="en">VU#768681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39920" xml:lang="en">application-rpc-config3-bo(39920)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3127" xml:lang="en">ADV-2008-3127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/32261" xml:lang="en">32261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/310.html" xml:lang="en">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32618" xml:lang="en">32618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.iss.net/archive/trend.html" xml:lang="en">http://blogs.iss.net/archive/trend.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-2008-0012 and CVE-2008-0013.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:-:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:-:sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:professional_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:-:sp2:itanium</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0015</vuln:cve-id>
    <vuln:published-datetime>2009-07-07T19:30:00.187-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:15:06.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-07-08T09:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7436" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7436" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6363" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6363" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6333" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6333" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" xml:lang="en">TA09-223A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" xml:lang="en">TA09-195A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-187A.html" xml:lang="en">TA09-187A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/180513" xml:lang="en">VU#180513</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/2232" xml:lang="en">ADV-2009-2232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022514" xml:lang="en">1022514</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/35585" xml:lang="en">35585</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/35558" xml:lang="en">35558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-037.mspx" xml:lang="en">MS09-037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-032.mspx" xml:lang="en">MS09-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/advisory/972890.mspx" xml:lang="en">http://www.microsoft.com/technet/security/advisory/972890.mspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/329.html" xml:lang="en">20090706 Multiple Microsoft Video Control ActiveX Remote Code Execution Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.csis.dk/dk/nyheder/nyheder.asp?tekstID=799" xml:lang="en">http://www.csis.dk/dk/nyheder/nyheder.asp?tekstID=799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/36187" xml:lang="en">36187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/55651" xml:lang="en">55651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isc.sans.org/diary.html?storyid=6733" xml:lang="en">http://isc.sans.org/diary.html?storyid=6733</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx" xml:lang="en">http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6363" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6363" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7436" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7436" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6333" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6333" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9_rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.99"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0::alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0::dev</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.99</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9_rc</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0::alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9:rc</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0016</vuln:cve-id>
    <vuln:published-datetime>2008-09-24T16:37:04.453-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-29T23:04:55.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-09-25T13:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11579" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11579" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=443288" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=443288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01403.html" xml:lang="en">FEDORA-2008-8429</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01384.html" xml:lang="en">FEDORA-2008-8401</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=451617" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=451617</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0977" xml:lang="en">ADV-2009-0977</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2661" xml:lang="en">ADV-2008-2661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-645-2" xml:lang="en">USN-645-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-645-1" xml:lang="en">USN-645-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1020913" xml:lang="en">1020913</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/31397" xml:lang="en">31397</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0908.html" xml:lang="en">RHSA-2008:0908</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0882.html" xml:lang="en">RHSA-2008:0882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2008/mfsa2008-37.html" xml:lang="en">http://www.mozilla.org/security/announce/2008/mfsa2008-37.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:206" xml:lang="en">MDVSA-2008:206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:205" xml:lang="en">MDVSA-2008:205</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1697" xml:lang="en">DSA-1697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1696" xml:lang="en">DSA-1696</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1669" xml:lang="en">DSA-1669</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1649" xml:lang="en">DSA-1649</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1" xml:lang="en">256408</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.412123" xml:lang="en">SSA:2008-270-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.405232" xml:lang="en">SSA:2008-269-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.379422" xml:lang="en">SSA:2008-269-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34501" xml:lang="en">34501</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33434" xml:lang="en">33434</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33433" xml:lang="en">33433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32845" xml:lang="en">32845</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32196" xml:lang="en">32196</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32185" xml:lang="en">32185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32144" xml:lang="en">32144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32092" xml:lang="en">32092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32082" xml:lang="en">32082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32044" xml:lang="en">32044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32042" xml:lang="en">32042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32012" xml:lang="en">32012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32010" xml:lang="en">32010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31985" xml:lang="en">31985</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31984" xml:lang="en">31984</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.html" xml:lang="en">SUSE-SA:2008:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://download.novell.com/Download?buildid=WZXONb-tqBw~" xml:lang="en">http://download.novell.com/Download?buildid=WZXONb-tqBw~</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11579" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11579" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0017</vuln:cve-id>
    <vuln:published-datetime>2008-11-13T06:30:01.173-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:50:05.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-11-13T13:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11005" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11005" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-319A.html" xml:lang="en">TA08-319A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html" xml:lang="en">FEDORA-2008-9669</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html" xml:lang="en">FEDORA-2008-9667</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=443299" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=443299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0977" xml:lang="en">ADV-2009-0977</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3146" xml:lang="en">ADV-2008-3146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021185" xml:lang="en">1021185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/32281" xml:lang="en">32281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0978.html" xml:lang="en">RHSA-2008:0978</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0977.html" xml:lang="en">RHSA-2008:0977</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2008/mfsa2008-54.html" xml:lang="en">http://www.mozilla.org/security/announce/2008/mfsa2008-54.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:230" xml:lang="en">MDVSA-2008:230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:228" xml:lang="en">MDVSA-2008:228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/311.html" xml:lang="en">20081113 Mozilla Unchecked Allocation Remote Code Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1697" xml:lang="en">DSA-1697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1671" xml:lang="en">DSA-1671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1669" xml:lang="en">DSA-1669</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-667-1" xml:lang="en">USN-667-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1" xml:lang="en">256408</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34501" xml:lang="en">34501</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33433" xml:lang="en">33433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32853" xml:lang="en">32853</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32845" xml:lang="en">32845</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32778" xml:lang="en">32778</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32721" xml:lang="en">32721</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32714" xml:lang="en">32714</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32713" xml:lang="en">32713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32695" xml:lang="en">32695</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32694" xml:lang="en">32694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32693" xml:lang="en">32693</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/32684" xml:lang="en">32684</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html" xml:lang="en">SUSE-SA:2008:055</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11005" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11005" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:-:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:-:sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:professional_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:-:sp2:itanium</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0020</vuln:cve-id>
    <vuln:published-datetime>2009-07-07T19:30:00.217-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-07-08T09:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5850" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5850" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" xml:lang="en">TA09-223A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/2232" xml:lang="en">ADV-2009-2232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-037.mspx" xml:lang="en">MS09-037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022712" xml:lang="en">1022712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/329.html" xml:lang="en">20090706 Multiple Microsoft Video Control ActiveX Remote Code Execution Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/36187" xml:lang="en">36187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx" xml:lang="en">http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5850" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5850" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption, aka "ATL Header Memcopy Vulnerability," a different vulnerability than CVE-2008-0015.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:5.0%281%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:5.0%282%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:5.0%283%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:5.0%283a%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:5.0%284%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:5.0_4a"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_3a"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_4"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_4a"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_4a_su1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.0_1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:unified_callmanager:5.0%283a%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_4a_su1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_callmanager:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.0_1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_4</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_callmanager:5.0%282%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_3</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_callmanager:6.0</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_callmanager:5.0_4a</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_callmanager:5.0%284%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_callmanager:5.1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_2</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.0</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_callmanager:5.0%283%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_4a</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_3a</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_callmanager:5.0%281%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0026</vuln:cve-id>
    <vuln:published-datetime>2008-02-14T07:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-08T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-14T14:03:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/40484" xml:lang="en">cucm-interface-sql-injection(40484)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0542" xml:lang="en">ADV-2008-0542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019404" xml:lang="en">1019404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27775" xml:lang="en">27775</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7c.shtml" xml:lang="en">20080213 SQL injection in Cisco Unified Communications Manager</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28932" xml:lang="en">28932</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:4.1%283%29sr4"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:4.1%283%29sr5"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_callmanager:4.1%283%29sr5b"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:4.2.3sr2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:4.2.3sr2b"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:unified_callmanager:4.1%283%29sr5</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:4.2.3sr2b</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_callmanager:4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:4.2.3sr2</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:4.2</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_callmanager:4.1%283%29sr4</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_callmanager:4.1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_callmanager:4.1%283%29sr5b</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0027</vuln:cve-id>
    <vuln:published-datetime>2008-01-16T22:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:48.080-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-17T11:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080932c61.shtml" xml:lang="en">20080116 Cisco Unified Communications Manager CTL Provider Heap Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39704" xml:lang="en">cisco-cucm-ctl-bo(39704)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0171" xml:lang="en">ADV-2008-0171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27313" xml:lang="en">27313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/486432/100/0/threaded" xml:lang="en">20080116 TPTI-08-02: Cisco Call Manager CTLProvider Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://dvlabs.tippingpoint.com/advisory/TPTI-08-02" xml:lang="en">http://dvlabs.tippingpoint.com/advisory/TPTI-08-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019223" xml:lang="en">1019223</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3551" xml:lang="en">3551</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28530" xml:lang="en">28530</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code via a long request.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:5500_adaptive_security_appliance:7.2:2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:5500_series_adaptive_security_appliance:8.0:2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:7.2%282%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:8.0%282%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:pix_firewall:8.0%282%29</vuln:product>
      <vuln:product>cpe:/h:cisco:5500_adaptive_security_appliance:7.2:2</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:7.2%282%29</vuln:product>
      <vuln:product>cpe:/h:cisco:5500_series_adaptive_security_appliance:8.0:2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0028</vuln:cve-id>
    <vuln:published-datetime>2008-01-23T16:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-23T16:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39862" xml:lang="en">pix-asa-ttl-dos(39862)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0259" xml:lang="en">ADV-2008-0259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019263" xml:lang="en">1019263</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019262" xml:lang="en">1019262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27418" xml:lang="en">27418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20080123-asa.shtml" xml:lang="en">20080123 Cisco PIX and ASA Time-to-Live Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28625" xml:lang="en">28625</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Security Appliance (ASA) before 7.2(3)6 and 8.0(3), when the Time-to-Live (TTL) decrement feature is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted IP packet.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:cisco:application_velocity_system_3110"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:application_velocity_system_3120"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:application_velocity_system_3180"/>
          <cpe-lang:fact-ref name="cpe:/h:cisco:application_velocity_system_3180a"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:cisco:application_velocity_system:5.0.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:application_velocity_system:5.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0029</vuln:cve-id>
    <vuln:published-datetime>2008-01-23T16:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:48.283-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-23T17:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0260" xml:lang="en">ADV-2008-0260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20080123-avs.shtml" xml:lang="en">20080123 Default Passwords in the Application Velocity System</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39860" xml:lang="en">ciscoavs-default-password-admin-account(39860)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019259" xml:lang="en">1019259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27421" xml:lang="en">27421</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0031</vuln:cve-id>
    <vuln:published-datetime>2008-01-15T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-20T22:48:54.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-16T11:46:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-016A.html" xml:lang="en">TA08-016A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0148" xml:lang="en">ADV-2008-0148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html" xml:lang="en">APPLE-SA-2008-01-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307301" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39695" xml:lang="en">quicktime-sorenson-code-execution(39695)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019221" xml:lang="en">1019221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27298" xml:lang="en">27298</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28502" xml:lang="en">28502</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Sorenson 3 video file, which triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0032">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0032</vuln:cve-id>
    <vuln:published-datetime>2008-01-15T22:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:48.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-16T13:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-016A.html" xml:lang="en">TA08-016A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=642" xml:lang="en">20080115 Apple QuickTime Macintosh Resource Processing Heap Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0148" xml:lang="en">ADV-2008-0148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html" xml:lang="en">APPLE-SA-2008-01-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307301" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39696" xml:lang="en">quicktime-macintosh-code-execution(39696)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019221" xml:lang="en">1019221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27301" xml:lang="en">27301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28502" xml:lang="en">28502</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file containing a Macintosh Resource record with a modified length value in the resource header, which triggers heap corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1.70"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1.70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0033</vuln:cve-id>
    <vuln:published-datetime>2008-01-15T22:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-16T13:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-016A.html" xml:lang="en">TA08-016A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39697" xml:lang="en">quicktime-idsc-code-execution(39697)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0148" xml:lang="en">ADV-2008-0148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019221" xml:lang="en">1019221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27299" xml:lang="en">27299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/486413/100/0/threaded" xml:lang="en">20080115 TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28502" xml:lang="en">28502</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html" xml:lang="en">APPLE-SA-2008-01-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://dvlabs.tippingpoint.com/advisory/TPTI-08-01" xml:lang="en">http://dvlabs.tippingpoint.com/advisory/TPTI-08-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307301" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307301</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a movie file with Image Descriptor (IDSC) atoms containing an invalid atom size, which triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:apple:iphone:1.0"/>
        <cpe-lang:fact-ref name="cpe:/h:apple:iphone:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:apple:iphone:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/h:apple:iphone:1.02"/>
        <cpe-lang:fact-ref name="cpe:/h:apple:iphone:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/h:apple:iphone:1.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:apple:iphone:1.0.2</vuln:product>
      <vuln:product>cpe:/h:apple:iphone:1.1.1</vuln:product>
      <vuln:product>cpe:/h:apple:iphone:1.0</vuln:product>
      <vuln:product>cpe:/h:apple:iphone:1.1.2</vuln:product>
      <vuln:product>cpe:/h:apple:iphone:1.0.1</vuln:product>
      <vuln:product>cpe:/h:apple:iphone:1.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0034</vuln:cve-id>
    <vuln:published-datetime>2008-01-15T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:48.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-16T11:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0147" xml:lang="en">ADV-2008-0147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Jan/msg00000.html" xml:lang="en">APPLE-SA-2008-01-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307302" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307302</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39701" xml:lang="en">iphone-passcode-lock-security-bypass(39701)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019219" xml:lang="en">1019219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27297" xml:lang="en">27297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28497" xml:lang="en">28497</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Passcode Lock in Apple iPhone 1.0 through 1.1.2 allows users with physical access to execute applications without entering the passcode via vectors related to emergency calls.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:apple:iphone:1.0"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:iphone:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:iphone:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:iphone:1.02"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:iphone:1.1.1"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:iphone:1.1.2"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:ipod_touch:1.1"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:ipod_touch:1.1.1"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:ipod_touch:1.1.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:safari"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0035</vuln:cve-id>
    <vuln:published-datetime>2008-01-15T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-05-13T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-16T11:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" xml:lang="en">TA08-043B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39700" xml:lang="en">iphone-ipod-foundation-code-execution(39700)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0495/references" xml:lang="en">ADV-2008-0495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0147" xml:lang="en">ADV-2008-0147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019220" xml:lang="en">1019220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27296" xml:lang="en">27296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28891" xml:lang="en">28891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28497" xml:lang="en">28497</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Jan/msg00000.html" xml:lang="en">APPLE-SA-2008-01-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" xml:lang="en">APPLE-SA-2008-02-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307430" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307430</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307302" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307302</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Foundation, as used in Apple iPhone 1.0 through 1.1.2, iPod touch 1.1 through 1.1.2, and Mac OS X 10.5 through 10.5.1, allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted URL that triggers memory corruption in Safari.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0036">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0036</vuln:cve-id>
    <vuln:published-datetime>2008-01-15T22:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:49.110-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-16T13:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-016A.html" xml:lang="en">TA08-016A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2064/references" xml:lang="en">ADV-2008-2064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0148" xml:lang="en">ADV-2008-0148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31034" xml:lang="en">31034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html" xml:lang="en">APPLE-SA-2008-01-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.html" xml:lang="en">APPLE-SA-2008-07-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307301" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39698" xml:lang="en">quicktime-pict-bo(39698)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019221" xml:lang="en">1019221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27300" xml:lang="en">27300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28502" xml:lang="en">28502</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a crafted compressed PICT image, which triggers the overflow during decoding.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0037">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0037</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T15:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:49.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T15:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" xml:lang="en">TA08-043B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" xml:lang="en">APPLE-SA-2008-02-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0495/references" xml:lang="en">ADV-2008-0495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019365" xml:lang="en">1019365</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27736" xml:lang="en">27736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28891" xml:lang="en">28891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307430" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307430</vuln:reference>
    </vuln:references>
    <vuln:summary>X11 in Apple Mac OS X 10.5 through 10.5.1 does not properly handle when the "Allow connections from network client" preference is disabled, which allows remote attackers to bypass intended access restrictions and connect to the X server.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0038</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T15:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:49.297-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T15:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" xml:lang="en">TA08-043B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" xml:lang="en">APPLE-SA-2008-02-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0495/references" xml:lang="en">ADV-2008-0495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019360" xml:lang="en">1019360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27736" xml:lang="en">27736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28891" xml:lang="en">28891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307430" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307430</vuln:reference>
    </vuln:references>
    <vuln:summary>Launch Services in Apple Mac OS X 10.5 through 10.5.1 allows an uninstalled application to be launched if it is in a Time Machine backup, which might allow local users to bypass intended security restrictions or exploit vulnerabilities in the application.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:mail"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:mail</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0039</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T15:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:49.377-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T15:31:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" xml:lang="en">TA08-043B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" xml:lang="en">APPLE-SA-2008-02-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0495/references" xml:lang="en">ADV-2008-0495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019361" xml:lang="en">1019361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27736" xml:lang="en">27736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28891" xml:lang="en">28891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307430" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307430</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Mail in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary commands via a crafted file:// URL.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0040</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T15:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:49.487-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T15:34:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" xml:lang="en">TA08-043B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" xml:lang="en">APPLE-SA-2008-02-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0495/references" xml:lang="en">ADV-2008-0495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019362" xml:lang="en">1019362</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27736" xml:lang="en">27736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28891" xml:lang="en">28891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307430" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307430</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in NFS in Apple Mac OS X 10.5 through 10.5.1 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via unknown vectors related to mbuf chains that trigger memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0041">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0041</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T15:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:49.563-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T15:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" xml:lang="en">TA08-043B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" xml:lang="en">APPLE-SA-2008-02-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0495/references" xml:lang="en">ADV-2008-0495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019363" xml:lang="en">1019363</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27736" xml:lang="en">27736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28891" xml:lang="en">28891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307430" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307430</vuln:reference>
    </vuln:references>
    <vuln:summary>Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determine when a system is running Parental Controls.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0042</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T15:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:49.687-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T15:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" xml:lang="en">TA08-043B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/774345" xml:lang="en">VU#774345</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" xml:lang="en">APPLE-SA-2008-02-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0495/references" xml:lang="en">ADV-2008-0495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019364" xml:lang="en">1019364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27736" xml:lang="en">27736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28891" xml:lang="en">28891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307430" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307430</vuln:reference>
    </vuln:references>
    <vuln:summary>Argument injection vulnerability in Terminal.app in Terminal in Apple Mac OS X 10.4.11 and 10.5 through 10.5.1 allows remote attackers to execute arbitrary code via unspecified URL schemes.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:iphoto:7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:iphoto:7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0043</vuln:cve-id>
    <vuln:published-datetime>2008-02-07T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:49.767-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-08T13:05:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Feb/msg00000.html" xml:lang="en">APPLE-SA-2008-02-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0428/references" xml:lang="en">ADV-2008-0428</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019307" xml:lang="en">1019307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28805" xml:lang="en">28805</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307398" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307398</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27636" xml:lang="en">27636</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrary code via photocast subscriptions.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0044">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0044</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T18:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:49.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T10:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41319" xml:lang="en">macos-afpclient-bo(41319)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019640" xml:lang="en">1019640</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28320" xml:lang="en">28320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in AFP Client in Apple Mac OS X 10.4.11 and 10.5.2 allow remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted afp:// URL.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0045</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T18:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:49.953-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T10:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41318" xml:lang="en">macos-afpserver-security-bypass(41318)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019642" xml:lang="en">1019642</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28323" xml:lang="en">28323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass cross-realm authentication via unknown manipulations of Kerberos principal realm names.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0046</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T18:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:50.047-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T10:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41317" xml:lang="en">macos-applicationfirewall-weak-security(41317)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019658" xml:lang="en">1019658</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28368" xml:lang="en">28368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the "Set access for specific services and applications" radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:cups:cups:1.3.5"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cups:cups:1.3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0047</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T12:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10085" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10085" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00105.html" xml:lang="en">FEDORA-2008-2897</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00091.html" xml:lang="en">FEDORA-2008-2131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0921/references" xml:lang="en">ADV-2008-0921</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-598-1" xml:lang="en">USN-598-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019646" xml:lang="en">1019646</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28307" xml:lang="en">28307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0192.html" xml:lang="en">RHSA-2008:0192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:081" xml:lang="en">MDVSA-2008:081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1530" xml:lang="en">DSA-1530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200804-01.xml" xml:lang="en">GLSA-200804-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29750" xml:lang="en">29750</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29655" xml:lang="en">29655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29634" xml:lang="en">29634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29603" xml:lang="en">29603</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29573" xml:lang="en">29573</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29485" xml:lang="en">29485</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29448" xml:lang="en">29448</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29431" xml:lang="en">29431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00005.html" xml:lang="en">SUSE-SA:2008:015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=674" xml:lang="en">20080318 Multiple Vendor CUPS CGI Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10085" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10085" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0048</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T18:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:50.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T10:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41315" xml:lang="en">macos-appkit-nsdocument-bo(41315)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019647" xml:lang="en">1019647</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28388" xml:lang="en">28388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via the a long file name to the NSDocument API.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0049</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T18:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:50.330-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T10:48:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41314" xml:lang="en">macos-appkit-code-execution(41314)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019647" xml:lang="en">1019647</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28340" xml:lang="en">28340</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:summary>AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-process communication instead of inter-thread communication, which allows local users to execute arbitrary code via crafted messages to privileged applications.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0050</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T18:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:50.423-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T10:55:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41313" xml:lang="en">macos-cfnetwork-502badgateway-spoofing(41313)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2094/references" xml:lang="en">ADV-2008-2094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0920/references" xml:lang="en">ADV-2008-0920</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019655" xml:lang="en">1019655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31074" xml:lang="en">31074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html" xml:lang="en">APPLE-SA-2008-07-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307563" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28356" xml:lang="en">28356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28290" xml:lang="en">28290</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:summary>CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0051</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T18:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:50.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T11:01:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41310" xml:lang="en">macos-corefoundation-timezone-code-execution(41310)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019670" xml:lang="en">1019670</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28375" xml:lang="en">28375</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in CoreFoundation in Apple Mac OS X 10.4.11 might allow local users to execute arbitrary code via crafted time zone data.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0052">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0052</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:50.627-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T12:27:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41312" xml:lang="en">macos-coreservices-weak-security(41312)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019671" xml:lang="en">1019671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28384" xml:lang="en">28384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.5-1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.5-2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.6-1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.9-1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.10-1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.6-3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.6-2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.21:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.21:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.23:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.22:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.22:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2:b2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2:b1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.23"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3:b1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:cups:1.3.9</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.8</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.5-1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.16</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.9-1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.6</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.14</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.23:rc1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.6-1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.22</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.13</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2:b1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.12</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.9</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.21:rc2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.11</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.6-2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2:b2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.7</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3:rc1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.8</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.9</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3:b1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.22:rc1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.22:rc2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.21:rc1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2:rc3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.10-1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.5-2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.7</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.6-3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.21</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2:rc2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.18</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc6</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3:rc2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.23</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.6</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.10</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.15</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.17</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2:rc1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.11</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0053</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-05-13T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T12:32:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10356" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10356" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00105.html" xml:lang="en">FEDORA-2008-2897</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41272" xml:lang="en">macos-cups-inputvalidation-unspecified(41272)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-598-1" xml:lang="en">USN-598-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019672" xml:lang="en">1019672</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28334" xml:lang="en">28334</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0206.html" xml:lang="en">RHSA-2008:0206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0192.html" xml:lang="en">RHSA-2008:0192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:081" xml:lang="en">MDVSA-2008:081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1625" xml:lang="en">DSA-1625</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200804-01.xml" xml:lang="en">GLSA-200804-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31324" xml:lang="en">31324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29750" xml:lang="en">29750</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29659" xml:lang="en">29659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29655" xml:lang="en">29655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29634" xml:lang="en">29634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29630" xml:lang="en">29630</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29603" xml:lang="en">29603</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29573" xml:lang="en">29573</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00003.html" xml:lang="en">SUSE-SA:2008:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10356" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10356" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remote attackers to execute arbitrary code via a crafted HP-GL/2 file.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0054</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:50.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T12:37:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41355" xml:lang="en">macos-nsselectorfromstring-code-execution(41355)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019649" xml:lang="en">1019649</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28341" xml:lang="en">28341</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0055</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:51.063-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T12:40:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41299" xml:lang="en">macos-nsfilemanager-priv-escalation(41299)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019649" xml:lang="en">1019649</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28343" xml:lang="en">28343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibly gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0056</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:51.157-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T12:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41309" xml:lang="en">macos-foundation-nsfilemanager-bo(41309)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019649" xml:lang="en">1019649</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28357" xml:lang="en">28357</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Foundation in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a "long pathname with an unexpected structure" that triggers the overflow in NSFileManager.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0057</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T18:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T11:06:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41298" xml:lang="en">macos-appkit-parser-bo(41298)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019648" xml:lang="en">1019648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28358" xml:lang="en">28358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple integer overflows in a "legacy serialization format" parser in AppKit in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via a crafted serialized property list.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0058</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:51.563-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T12:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41297" xml:lang="en">macos-foundation-nsurl-code-execution(41297)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019650" xml:lang="en">1019650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28359" xml:lang="en">28359</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0059</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:51.657-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T12:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41296" xml:lang="en">macos-foundation-code-execution(41296)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019650" xml:lang="en">1019650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28367" xml:lang="en">28367</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0060">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0060</vuln:cve-id>
    <vuln:published-datetime>2008-03-18T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:51.767-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T12:49:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" xml:lang="en">TA08-079A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41295" xml:lang="en">macos-helpviewer-code-execution(41295)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019657" xml:lang="en">1019657</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28371" xml:lang="en">28371</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28304" xml:lang="en">28304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:summary>Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0061">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.00"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.01"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.02"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.03"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.04"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.05"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.06"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.07"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.08"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.09"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.25"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.30"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.31"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.33"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.34"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.01"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.02"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.03"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.04"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.05"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.06"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.2.12.07"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.01"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.02"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.03"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.04"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.05"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.06"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.07"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.07.01"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.07.02"/>
        <cpe-lang:fact-ref name="cpe:/a:maradns:maradns:1.3.07.03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:maradns:maradns:1.0.12</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.29</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.2.12.01</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.36</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.26</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.3.02</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.01</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.19</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.18</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.30</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.16</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.32</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.15</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.3.07.02</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.2.12.07</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.07</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.33</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.3.07</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.05</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.14</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.13</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.06</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.2.12.04</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.2.12.06</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.34</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.20</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.3.07.01</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.3.04</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.39</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.25</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.2.12.03</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.35</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.10</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.17</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.00</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.09</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.27</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.04</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.28</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.3.01</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.2.12.02</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.02</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.23</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.2.12.05</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.3.07.03</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.38</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.22</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.24</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.11</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.37</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.31</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.03</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.21</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.3.03</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.0.08</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.3.06</vuln:product>
      <vuln:product>cpe:/a:maradns:maradns:1.3.05</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0061</vuln:cve-id>
    <vuln:published-datetime>2008-01-03T17:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:51.907-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-04T08:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0026" xml:lang="en">ADV-2008-0026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.maradns.org/changelog.html" xml:lang="en">http://www.maradns.org/changelog.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://maradns.blogspot.com/2007/08/maradns-update-all-versions.html" xml:lang="en">http://maradns.blogspot.com/2007/08/maradns-update-all-versions.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27124" xml:lang="en">27124</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1445" xml:lang="en">DSA-1445</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200801-16.xml" xml:lang="en">GLSA-200801-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28650" xml:lang="en">28650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28334" xml:lang="en">28334</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28329" xml:lang="en">28329</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=204351" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=204351</vuln:reference>
    </vuln:references>
    <vuln:summary>MaraDNS 1.0 before 1.0.41, 1.2 before 1.2.12.08, and 1.3 before 1.3.07.04 allows remote attackers to cause a denial of service via a crafted DNS packet that prevents an authoritative name (CNAME) record from resolving, aka "improper rotation of resource records."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0062">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mit:kerberos_5:1.6.3_kdc"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos_5:1.6.3_kdc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0062</vuln:cve-id>
    <vuln:published-datetime>2008-03-19T06:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-06T22:41:51.410-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T16:07:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9496" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9496" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/895609" xml:lang="en">VU#895609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt" xml:lang="en">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41275" xml:lang="en">krb5-kdc-code-execution(41275)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1744" xml:lang="en">ADV-2008-1744</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1102/references" xml:lang="en">ADV-2008-1102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0922/references" xml:lang="en">ADV-2008-0922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/489761" xml:lang="en">20080318 MITKRB5-SA-2008-001: double-free, uninitialized data vulnerabilities in krb5kdc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=130497213107107&amp;w=2" xml:lang="en">SSRT100495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=130497213107107&amp;w=2" xml:lang="en">HPSBOV02682</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html" xml:lang="en">FEDORA-2008-2647</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html" xml:lang="en">FEDORA-2008-2637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2008-0009.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2008-0009.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-587-1" xml:lang="en">USN-587-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019626" xml:lang="en">1019626</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28303" xml:lang="en">28303</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/493080/100/0/threaded" xml:lang="en">20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/489883/100/0/threaded" xml:lang="en">20080319 rPSA-2008-0112-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0182.html" xml:lang="en">RHSA-2008:0182</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0181.html" xml:lang="en">RHSA-2008:0181</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0180.html" xml:lang="en">RHSA-2008:0180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0164.html" xml:lang="en">RHSA-2008:0164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:071" xml:lang="en">MDVSA-2008:071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:070" xml:lang="en">MDVSA-2008:070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:069" xml:lang="en">MDVSA-2008:069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200803-31.xml" xml:lang="en">GLSA-200803-31</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1524" xml:lang="en">DSA-1524</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112" xml:lang="en">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2008-0112" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2008-0112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html" xml:lang="en">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html" xml:lang="en">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30535" xml:lang="en">30535</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29663" xml:lang="en">29663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29516" xml:lang="en">29516</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29464" xml:lang="en">29464</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29462" xml:lang="en">29462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29457" xml:lang="en">29457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29451" xml:lang="en">29451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29450" xml:lang="en">29450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29438" xml:lang="en">29438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29435" xml:lang="en">29435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29428" xml:lang="en">29428</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29424" xml:lang="en">29424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29423" xml:lang="en">29423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html" xml:lang="en">SUSE-SA:2008:016</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9496" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9496" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mit:kerberos_5:1.6.3_kdc"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos_5:1.6.3_kdc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0063</vuln:cve-id>
    <vuln:published-datetime>2008-03-19T06:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-19T16:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8916" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8916" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt" xml:lang="en">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html" xml:lang="en">FEDORA-2008-2647</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html" xml:lang="en">FEDORA-2008-2637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41277" xml:lang="en">krb5-kdc-kerberos4-info-disclosure(41277)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1744" xml:lang="en">ADV-2008-1744</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1102/references" xml:lang="en">ADV-2008-1102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0922/references" xml:lang="en">ADV-2008-0922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2008-0009.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2008-0009.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-587-1" xml:lang="en">USN-587-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019627" xml:lang="en">1019627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28303" xml:lang="en">28303</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/493080/100/0/threaded" xml:lang="en">20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/489883/100/0/threaded" xml:lang="en">20080319 rPSA-2008-0112-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/489761" xml:lang="en">20080318 MITKRB5-SA-2008-001: double-free, uninitialized data vulnerabilities in krb5kdc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0182.html" xml:lang="en">RHSA-2008:0182</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0181.html" xml:lang="en">RHSA-2008:0181</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0180.html" xml:lang="en">RHSA-2008:0180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0164.html" xml:lang="en">RHSA-2008:0164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:071" xml:lang="en">MDVSA-2008:071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:070" xml:lang="en">MDVSA-2008:070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:069" xml:lang="en">MDVSA-2008:069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200803-31.xml" xml:lang="en">GLSA-200803-31</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1524" xml:lang="en">DSA-1524</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112" xml:lang="en">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2008-0112" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2008-0112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html" xml:lang="en">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html" xml:lang="en">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30535" xml:lang="en">30535</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29663" xml:lang="en">29663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29516" xml:lang="en">29516</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29464" xml:lang="en">29464</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29462" xml:lang="en">29462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29457" xml:lang="en">29457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29451" xml:lang="en">29451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29450" xml:lang="en">29450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29438" xml:lang="en">29438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29435" xml:lang="en">29435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29428" xml:lang="en">29428</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29424" xml:lang="en">29424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29423" xml:lang="en">29423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29420" xml:lang="en">29420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html" xml:lang="en">SUSE-SA:2008:016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8916" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8916" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pierreegougelet:gfl_sdk:2.870::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:pierreegougelet:nconvert:4.85"/>
        <cpe-lang:fact-ref name="cpe:/a:pierreegougelet:xnview:1.91"/>
        <cpe-lang:fact-ref name="cpe:/a:pierreegougelet:xnview:1.92"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pierreegougelet:nconvert:4.85</vuln:product>
      <vuln:product>cpe:/a:pierreegougelet:xnview:1.91</vuln:product>
      <vuln:product>cpe:/a:pierreegougelet:gfl_sdk:2.870::windows</vuln:product>
      <vuln:product>cpe:/a:pierreegougelet:xnview:1.92</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0064</vuln:cve-id>
    <vuln:published-datetime>2008-01-31T15:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:52.297-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-01T10:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28326" xml:lang="en">28326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0329" xml:lang="en">ADV-2008-0329</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0328" xml:lang="en">ADV-2008-0328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27514" xml:lang="en">27514</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2008-1/advisory" xml:lang="en">http://secunia.com/secunia_research/2008-1/advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28710" xml:lang="en">28710</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Pierre-emmanuel Gougelet (1) XnView 1.91 and 1.92, (2) NConvert 4.85, and (3) libgfl280.dll in GFL SDK 2.870 for Windows allows user-assisted remote attackers to execute arbitrary code via a crafted Radiance RGBE (.hdr) file.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:winamp:nullsoft_winamp:5.21"/>
        <cpe-lang:fact-ref name="cpe:/a:winamp:nullsoft_winamp:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:winamp:nullsoft_winamp:5.51"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:winamp:nullsoft_winamp:5.5</vuln:product>
      <vuln:product>cpe:/a:winamp:nullsoft_winamp:5.21</vuln:product>
      <vuln:product>cpe:/a:winamp:nullsoft_winamp:5.51</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0065</vuln:cve-id>
    <vuln:published-datetime>2008-01-22T15:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:52.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-23T09:29:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.winamp.com/player/version-history" xml:lang="en">http://www.winamp.com/player/version-history</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0183" xml:lang="en">ADV-2008-0183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2008-2/advisory/" xml:lang="en">http://secunia.com/secunia_research/2008-2/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/27865" xml:lang="en">27865</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39778" xml:lang="en">winamp-inmp3-bo(39778)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27344" xml:lang="en">27344</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:autonomy:keyview"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:7.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:autonomy:keyview</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:7.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0066</vuln:cve-id>
    <vuln:published-datetime>2008-04-10T14:05:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:52.580-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-04-10T15:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41724" xml:lang="en">autonomy-keyview-html-multiple-bo(41724)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1156" xml:lang="en">ADV-2008-1156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1153" xml:lang="en">ADV-2008-1153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019843" xml:lang="en">1019843</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28454" xml:lang="en">28454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/490828/100/0/threaded" xml:lang="en">20080414 Secunia Research: Lotus Notes htmsr.dll Buffer Overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21298453" xml:lang="en">http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21298453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2008-3/advisory/" xml:lang="en">http://secunia.com/secunia_research/2008-3/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28210" xml:lang="en">28210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28209" xml:lang="en">28209</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28140" xml:lang="en">28140</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allow remote attackers to execute arbitrary code via an HTML document with (1) "large chunks of data," or a long URL in the (2) BACKGROUND attribute of a BODY element or (3) SRC attribute of an IMG element.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.51"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.51</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0067</vuln:cve-id>
    <vuln:published-datetime>2009-01-08T14:30:00.407-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-21T22:48:46.553-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-08T15:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33147" xml:lang="en">33147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499826/100/0/threaded" xml:lang="en">20090107 Secunia Research: HP OpenView Network Node Manager Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1021521" xml:lang="en">1021521</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/8307" xml:lang="en">8307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4885" xml:lang="en">4885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2008-13/" xml:lang="en">http://secunia.com/secunia_research/2008-13/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28074" xml:lang="en">28074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=123247393715913&amp;w=2" xml:lang="en">SSRT080144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=123247393715913&amp;w=2" xml:lang="en">SSRT080144</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) long string parameters to the OpenView5.exe CGI program; (2) a long string parameter to the OpenView5.exe CGI program, related to ov.dll; or a long string parameter to the (3) getcvdata.exe, (4) ovlaunch.exe, or (5) Toolbar.exe CGI program.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.51"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.53"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.51</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.53</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0068</vuln:cve-id>
    <vuln:published-datetime>2008-04-16T14:05:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:50:10.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-04-17T12:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41790" xml:lang="en">hpopenview-openview5-directory-traversal(41790)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1214/references" xml:lang="en">ADV-2008-1214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28745" xml:lang="en">28745</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/490834/100/0/threaded" xml:lang="en">20080414 Secunia Research: HP OpenView Network Node Manager OpenView5.exeDirectory Traversal</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/490771" xml:lang="en">20080411 Directory traversal and multiple Denials of Service in HP OpenView NNM 7.53</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3814" xml:lang="en">3814</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121553649611253&amp;w=2" xml:lang="en">HPSBMA02349</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121553649611253&amp;w=2" xml:lang="en">HPSBMA02349</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/closedviewx-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/closedviewx-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019839" xml:lang="en">1019839</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019838" xml:lang="en">1019838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/44359" xml:lang="en">44359</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2008-4/advisory/" xml:lang="en">http://secunia.com/secunia_research/2008-4/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29796" xml:lang="en">29796</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in OpenView5.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to read arbitrary files via directory traversal sequences in the Action parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pierreegougelet:xnview:1.92"/>
        <cpe-lang:fact-ref name="cpe:/a:pierreegougelet:xnview:1.92.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pierreegougelet:xnview:1.92</vuln:product>
      <vuln:product>cpe:/a:pierreegougelet:xnview:1.92.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0069</vuln:cve-id>
    <vuln:published-datetime>2008-04-02T13:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:52.830-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-04-02T14:12:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29620" xml:lang="en">29620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41542" xml:lang="en">xnview-slideshow-bo(41542)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1044/references" xml:lang="en">ADV-2008-1044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28579" xml:lang="en">28579</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/5346" xml:lang="en">5346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2008-6/advisory/" xml:lang="en">http://secunia.com/secunia_research/2008-6/advisory/</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long FontName parameter in a slideshow (.sld) file, a different vector than CVE-2008-1461.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0070">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:orb_networks:orb:2.0.1014"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:orb_networks:orb:2.0.1014</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0070</vuln:cve-id>
    <vuln:published-datetime>2008-03-31T13:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:52.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-31T20:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41410" xml:lang="en">orb-dimensions-bo(41410)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0984/references" xml:lang="en">ADV-2008-0984</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28431" xml:lang="en">28431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2008-5/advisory/" xml:lang="en">http://secunia.com/secunia_research/2008-5/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28203" xml:lang="en">28203</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in Orb Networks Orb 2.00.1014 and Winamp Remote BETA allows remote attackers to execute arbitrary code via an RPC request that specifies a large number of array dimensions, which triggers a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:3.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.20.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.20.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.20.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.20.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.20.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.20.8"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.20.9"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.22.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.22.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.22.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.24.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.24.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.26.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.27.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.27.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:4.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:5.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bittorrent:bittorrent:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.7.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:utorrent:utorrent:1.7</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.0.0</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.1.6</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:5.0.1</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.1.7</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.22.0</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:5.2.0</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:5.0.8</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.4.0</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.1.1</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.1.8</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.1.1</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:6.0.1</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.2.1</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:5.0.4</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.9.7</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:3.9.1</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.5</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.1.6</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.0.4</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.20.9</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.1.5</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.22.1</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.1.2</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.9.3</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.3.5</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.7.3</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.2.2</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:5.0.5</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.27.1</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.7.2</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.1.5</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.4.1</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.3.3</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.1.7</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.20.7</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.2.1</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.0.2</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.3.4</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.2.2</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.1.0</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.3.6</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.20.4</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.27.2</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.7.6</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.0.3</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.6</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.9.6</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:6.0.2</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.22.4</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.9.2</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.1.3</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.24.0</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.7.4</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.20.8</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:5.0.7</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.9.9</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:5.0.3</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.20.6</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.20.2</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.9.4</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.9.5</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.1.4</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.2.0</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.24.2</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.7.7</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:5.0.6</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.4</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.20.0</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.1.4</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:5.0.2</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.3.2</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.20.1</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:6.0</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:5.0.0</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.3.0</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.4.2</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.9.8</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.7.5</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.7.1</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.2</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:5.0.9</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.0.1</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.1.3</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.26.0</vuln:product>
      <vuln:product>cpe:/a:utorrent:utorrent:1.3</vuln:product>
      <vuln:product>cpe:/a:bittorrent:bittorrent:4.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0071</vuln:cve-id>
    <vuln:published-datetime>2008-06-16T14:41:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:53.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-06-17T09:33:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/29661" xml:lang="en">29661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1809" xml:lang="en">ADV-2008-1809</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1808" xml:lang="en">ADV-2008-1808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1020265" xml:lang="en">1020265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/493269/100/0/threaded" xml:lang="en">20080611 Secunia Research: uTorrent / BitTorrent Web UI HTTP "Range" Header DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/5918" xml:lang="en">5918</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1020266" xml:lang="en">1020266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3943" xml:lang="en">3943</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2008-7/advisory/" xml:lang="en">http://secunia.com/secunia_research/2008-7/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30605" xml:lang="en">30605</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28703" xml:lang="en">28703</vuln:reference>
    </vuln:references>
    <vuln:summary>The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a malformed Range header.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:gnome:evolution:2.12.3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:evolution:2.12.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0072</vuln:cve-id>
    <vuln:published-datetime>2008-03-05T19:44:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-06T13:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10701" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10701" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/512491" xml:lang="en">VU#512491</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1512" xml:lang="en">DSA-1512</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00195.html" xml:lang="en">FEDORA-2008-2292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00190.html" xml:lang="en">FEDORA-2008-2290</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-2310" xml:lang="en">https://issues.rpath.com/browse/RPL-2310</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41011" xml:lang="en">evolution-emfmultipart-format-string(41011)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0768/references" xml:lang="en">ADV-2008-0768</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-583-1" xml:lang="en">USN-583-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019540" xml:lang="en">1019540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28102" xml:lang="en">28102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/492684/100/0/threaded" xml:lang="en">20080528 rPSA-2008-0105-1 evolution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0178.html" xml:lang="en">RHSA-2008:0178</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0177.html" xml:lang="en">RHSA-2008:0177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:063" xml:lang="en">MDVSA-2008:063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0105" xml:lang="en">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200803-12.xml" xml:lang="en">GLSA-200803-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2008-8/advisory/" xml:lang="en">http://secunia.com/secunia_research/2008-8/advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30491" xml:lang="en">30491</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30437" xml:lang="en">30437</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29317" xml:lang="en">29317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29264" xml:lang="en">29264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29258" xml:lang="en">29258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29244" xml:lang="en">29244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29210" xml:lang="en">29210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29163" xml:lang="en">29163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29057" xml:lang="en">29057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00003.html" xml:lang="en">SUSE-SA:2008:014</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10701" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10701" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the Version field.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:redhat:fedora:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:xine:xine-lib:1.1.10.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xine:xine-lib:1.1.10.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0073</vuln:cve-id>
    <vuln:published-datetime>2008-03-24T18:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:54.237-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-25T10:44:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://xinehq.de/index.php/news" xml:lang="en">http://xinehq.de/index.php/news</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=585488&amp;group_id=9655" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=585488&amp;group_id=9655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41339" xml:lang="en">xinelib-sdpplinparse-bo(41339)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0985" xml:lang="en">ADV-2008-0985</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0923" xml:lang="en">ADV-2008-0923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-635-1" xml:lang="en">USN-635-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28312" xml:lang="en">28312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:219" xml:lang="en">MDVSA-2008:219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:178" xml:lang="en">MDVSA-2008:178</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200808-01.xml" xml:lang="en">GLSA-200808-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2008-10/" xml:lang="en">http://secunia.com/secunia_research/2008-10/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31393" xml:lang="en">31393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31372" xml:lang="en">31372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30581" xml:lang="en">30581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29503" xml:lang="en">29503</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28694" xml:lang="en">28694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00456.html" xml:lang="en">FEDORA-2008-2569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00143.html" xml:lang="en">FEDORA-2008-2945</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.videolan.org/security/sa0803.php" xml:lang="en">http://www.videolan.org/security/sa0803.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.392408" xml:lang="en">SSA:2008-089-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019682" xml:lang="en">1019682</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1543" xml:lang="en">DSA-1543</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1536" xml:lang="en">DSA-1536</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.videolan.org/Changelog/0.8.6f" xml:lang="en">http://wiki.videolan.org/Changelog/0.8.6f</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200804-25.xml" xml:lang="en">GLSA-200804-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29800" xml:lang="en">29800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29766" xml:lang="en">29766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29740" xml:lang="en">29740</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29601" xml:lang="en">29601</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29578" xml:lang="en">29578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29472" xml:lang="en">29472</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29392" xml:lang="en">29392</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html" xml:lang="en">SUSE-SR:2008:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00008.html" xml:lang="en">SUSE-SR:2008:007</vuln:reference>
    </vuln:references>
    <vuln:summary>Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:iis:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:6.0:beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:6.0:beta</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:iis:7.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0074</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T16:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:54.313-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T17:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5389" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5389" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0507/references" xml:lang="en">ADV-2008-0507</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019384" xml:lang="en">1019384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27101" xml:lang="en">27101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28849" xml:lang="en">28849</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">HPSBST02314</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5389" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5389" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:6.0:beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:6.0:beta</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0075</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T16:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:54.407-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T17:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5308" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5308" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0508/references" xml:lang="en">ADV-2008-0508</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019385" xml:lang="en">1019385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27676" xml:lang="en">27676</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28893" xml:lang="en">28893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">HPSBST02314</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5308" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5308" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:windows_2000_sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:windows_server_2003_sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:windows_server_2003_sp1_itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:windows_xp_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7:windows_server_2003_sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7:windows_xp_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6::windows_server_2003_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6::windows_server_2003_sp2_itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6::windows_server_2003_x64_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6::windows_server_2003_x64_edition_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6::windows_xp_professional_x64_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6::windows_xp_professional_x64_edition_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_server_2003_sp1_itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_server_2003_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_server_2003_sp2_itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_server_2003_x64_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_server_2003_x64_edition_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_vista"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_vista_x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_xp_professional_x64_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_xp_professional_x64_edition_sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_server_2003_x64_edition</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6::windows_xp_professional_x64_edition_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_server_2003_x64_edition_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6::windows_server_2003_x64_edition_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_server_2003_sp1_itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_xp_professional_x64_edition</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_vista_x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:windows_server_2003_sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_server_2003_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6::windows_server_2003_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.01:windows_2000_sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:windows_server_2003_sp1_itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6::windows_server_2003_x64_edition</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7:windows_xp_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_xp_professional_x64_edition_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6::windows_xp_professional_x64_edition</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:windows_xp_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_vista</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_server_2003_sp2_itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7:windows_server_2003_sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6::windows_server_2003_sp2_itanium</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0076</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:54.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-13T10:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5487" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5487" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0512/references" xml:lang="en">ADV-2008-0512</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-010.mspx" xml:lang="en">MS08-010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019379" xml:lang="en">1019379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27668" xml:lang="en">27668</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28903" xml:lang="en">28903</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">HPSBST02314</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5487" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5487" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka "HTML Rendering Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:gold:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:gold:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0077</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-13T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-13T11:17:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5396" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5396" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/228569" xml:lang="en">VU#228569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-010.mspx" xml:lang="en">MS08-010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-08-006.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-08-006.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0512/references" xml:lang="en">ADV-2008-0512</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019380" xml:lang="en">1019380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27666" xml:lang="en">27666</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/488048/100/0/threaded" xml:lang="en">20080213 ZDI-08-006: Microsoft Internet Explorer SVG animateMotion.by Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28903" xml:lang="en">28903</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=661" xml:lang="en">20080212 Microsoft Internet Explorer Property Memory Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5396" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5396" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, aka "Property Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:activex"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:windows_2000_sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:windows_server_2003_sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:windows_server_2003_sp1_itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:windows_xp_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7:windows_server_2003_sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7:windows_xp_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6::windows_server_2003_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6::windows_server_2003_sp2_itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6::windows_server_2003_x64_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6::windows_server_2003_x64_edition_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6::windows_xp_professional_x64_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6::windows_xp_professional_x64_edition_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_server_2003_sp1_itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_server_2003_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_server_2003_sp2_itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_server_2003_x64_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_server_2003_x64_edition_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_vista"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_vista_x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_xp_professional_x64_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7::windows_xp_professional_x64_edition_sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_server_2003_x64_edition</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6::windows_xp_professional_x64_edition_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_server_2003_x64_edition_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6::windows_server_2003_x64_edition_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_server_2003_sp1_itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_xp_professional_x64_edition</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_vista_x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:windows_server_2003_sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_server_2003_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6::windows_server_2003_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.01:windows_2000_sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:windows_server_2003_sp1_itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6::windows_server_2003_x64_edition</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7:windows_xp_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_xp_professional_x64_edition_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6::windows_xp_professional_x64_edition</vuln:product>
      <vuln:product>cpe:/a:microsoft:activex</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:windows_xp_sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_vista</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7::windows_server_2003_sp2_itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7:windows_server_2003_sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6::windows_server_2003_sp2_itanium</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0078</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:54.673-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-13T11:19:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4904" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4904" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0512/references" xml:lang="en">ADV-2008-0512</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-010.mspx" xml:lang="en">MS08-010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019381" xml:lang="en">1019381</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27689" xml:lang="en">27689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28903" xml:lang="en">28903</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">HPSBST02314</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4904" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4904" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka "Argument Handling Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:xp::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:2003:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:2003:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:webdav_mini-redirector"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:webdav_mini-redirector</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0080</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:54.767-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-13T11:33:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5381" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5381" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0509/references" xml:lang="en">ADV-2008-0509</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-007.mspx" xml:lang="en">MS08-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019372" xml:lang="en">1019372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27670" xml:lang="en">27670</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28894" xml:lang="en">28894</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">HPSBST02314</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5381" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5381" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0081</vuln:cve-id>
    <vuln:published-datetime>2008-01-16T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-15T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-17T10:29:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5546" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5546" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" xml:lang="en">TA08-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27305" xml:lang="en">27305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" xml:lang="en">MS08-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/advisory/947563.mspx" xml:lang="en">http://www.microsoft.com/technet/security/advisory/947563.mspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39699" xml:lang="en">microsoft-excel-unspecified-code-execution(39699)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0846/references" xml:lang="en">ADV-2008-0846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0146" xml:lang="en">ADV-2008-0146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/advisory/947563.mspx" xml:lang="en">947563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019200" xml:lang="en">1019200</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28506" xml:lang="en">28506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">SSRT080028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">SSRT080028</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5546" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5546" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_messenger:4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_messenger:5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_messenger:5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_messenger:4.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0082</vuln:cve-id>
    <vuln:published-datetime>2008-08-12T20:41:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:54.970-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-08-13T11:02:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5995" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5995" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-225A.html" xml:lang="en">TA08-225A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-050.mspx" xml:lang="en">MS08-050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2354" xml:lang="en">ADV-2008-2354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1020681" xml:lang="en">1020681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/30551" xml:lang="en">30551</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/495467/100/0/threaded" xml:lang="en">20080814 Microsoft Windows Messenger Remote Illegal Access Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31446" xml:lang="en">31446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121915960406986&amp;w=2" xml:lang="en">HPSBST02360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121915960406986&amp;w=2" xml:lang="en">HPSBST02360</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5995" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5995" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establish audio or video connections without notification via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0083</vuln:cve-id>
    <vuln:published-datetime>2008-04-08T19:05:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-04-09T08:59:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5495" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5495" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-099A.html" xml:lang="en">TA08-099A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28551" xml:lang="en">28551</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-022.mspx" xml:lang="en">MS08-022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1146/references" xml:lang="en">ADV-2008-1146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019799" xml:lang="en">1019799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29712" xml:lang="en">29712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120845064910729&amp;w=2" xml:lang="en">SSRT080048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120845064910729&amp;w=2" xml:lang="en">HPSBST02329</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5495" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5495" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0084</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T16:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:55.157-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T17:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5240" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5240" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0506/references" xml:lang="en">ADV-2008-0506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019383" xml:lang="en">1019383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27634" xml:lang="en">27634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28828" xml:lang="en">28828</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5240" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5240" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the TCP/IP support in Microsoft Windows Vista allows remote DHCP servers to cause a denial of service (hang and restart) via a crafted DHCP packet.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp4:itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server_desktop_engine:2000:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_engine:1.0:sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:wmsde:2000"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:wyukon::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:wmsde:2000"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:wyukon::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:wyukon::sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:wyukon::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server_desktop_engine:2000:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp1:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp2:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:wyukon::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp1:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:wmsde:2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_engine:1.0:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp2:express</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp1:express</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp4:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:wyukon::sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0085</vuln:cve-id>
    <vuln:published-datetime>2008-07-08T19:41:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:21:23.330-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-07-09T09:10:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14213" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14213" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-190A.html" xml:lang="en">TA08-190A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx" xml:lang="en">MS08-040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2022/references" xml:lang="en">ADV-2008-2022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1020441" xml:lang="en">1020441</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30970" xml:lang="en">30970</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14213" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14213" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_engine:1.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server_desktop_engine:2000:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server_express_edition:2005:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server_desktop_engine:2000:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_engine:1.0:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server_express_edition:2005:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0086</vuln:cve-id>
    <vuln:published-datetime>2008-07-08T19:41:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:21:23.500-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-07-09T09:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14052" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14052" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-190A.html" xml:lang="en">TA08-190A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2022/references" xml:lang="en">ADV-2008-2022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1020441" xml:lang="en">1020441</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/494082/100/0/threaded" xml:lang="en">20080708 Re: [Full-disclosure] iDefense Security Advisory 07.08.08: Microsoft SQL Server Restore Integer Underflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx" xml:lang="en">MS08-040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30970" xml:lang="en">30970</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14052" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14052" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:vista"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:xp::pro:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows-nt:xp:sp2:pro:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:xp:sp2:pro:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:xp::pro:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows-nt:vista</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0087</vuln:cve-id>
    <vuln:published-datetime>2008-04-08T19:05:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:55.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-04-09T09:59:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5314" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5314" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-099A.html" xml:lang="en">TA08-099A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28553" xml:lang="en">28553</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1144/references" xml:lang="en">ADV-2008-1144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.trusteer.com/docs/windowsresolver.html" xml:lang="en">http://www.trusteer.com/docs/windowsresolver.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019802" xml:lang="en">1019802</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/490575/100/0/threaded" xml:lang="en">20080408 Microsoft Windows DNS Stub Resolver Cache Poisoning (MS08-020)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-020.mspx" xml:lang="en">MS08-020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29696" xml:lang="en">29696</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120845064910729&amp;w=2" xml:lang="en">SSRT080048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120845064910729&amp;w=2" xml:lang="en">HPSBST02329</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5314" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5314" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0088</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T16:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:55.580-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T17:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5181" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5181" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0505/references" xml:lang="en">ADV-2008-0505</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-003.mspx" xml:lang="en">MS08-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019382" xml:lang="en">1019382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27638" xml:lang="en">27638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28764" xml:lang="en">28764</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">HPSBST02314</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5181" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5181" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:clip-share:clipshare"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clip-share:clipshare</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0089</vuln:cve-id>
    <vuln:published-datetime>2008-01-03T20:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-09-11T01:17:31.250-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-04T13:31:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27108" xml:lang="en">27108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4830" xml:lang="en">4830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28313" xml:lang="en">28313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/40077" xml:lang="en">40077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39364" xml:lang="en">clipshare-uprofile-sql-injection(39364)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in uprofile.php in ClipShare allows remote attackers to execute arbitrary SQL commands via the UID parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0090">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:divx:divx_player:6.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:7</vuln:product>
      <vuln:product>cpe:/a:divx:divx_player:6.6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0090</vuln:cve-id>
    <vuln:published-datetime>2008-01-03T20:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:11.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-04T13:34:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27106" xml:lang="en">27106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4829" xml:lang="en">4829</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39386" xml:lang="en">divxwebplayer-npUpload-dos(39386)</vuln:reference>
    </vuln:references>
    <vuln:summary>A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPassword method.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:agency4net:webftp:1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:agency4net:webftp:1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0091</vuln:cve-id>
    <vuln:published-datetime>2008-01-03T20:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:55.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-04T13:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0051" xml:lang="en">ADV-2008-0051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27092" xml:lang="en">27092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4828" xml:lang="en">4828</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2008-January/001865.html" xml:lang="en">20080104 true: AGENCY4NET WEBFTP directory traversal; deletion possible</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39343" xml:lang="en">agency4net-download2-directory-traversal(39343)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28309" xml:lang="en">28309</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0092">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpwebsite:phpwebsite:1.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpwebsite:phpwebsite:1.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0092</vuln:cve-id>
    <vuln:published-datetime>2008-01-03T20:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:11.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-04T13:51:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27090" xml:lang="en">27090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485704/100/0/threaded" xml:lang="en">20080101 Cross-Site Scripting (XSS) in phpWebSite 1.4.0 search</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://phpwebsite.appstate.edu/blog/2143" xml:lang="en">http://phpwebsite.appstate.edu/blog/2143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39391" xml:lang="en">phpwebsite-search-xss(39391)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3511" xml:lang="en">3511</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28303" xml:lang="en">28303</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eticket:eticket:1.5.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:eticket:eticket:1.5.6_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:eticket:eticket:1.5.6_rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eticket:eticket:1.5.6_rc3</vuln:product>
      <vuln:product>cpe:/a:eticket:eticket:1.5.5.2</vuln:product>
      <vuln:product>cpe:/a:eticket:eticket:1.5.6_rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0093</vuln:cve-id>
    <vuln:published-datetime>2008-01-07T20:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:11.857-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T10:19:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitrustgroup.com/advisories/web-application-security-eticket.html" xml:lang="en">http://www.digitrustgroup.com/advisories/web-application-security-eticket.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28331" xml:lang="en">28331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39400" xml:lang="en">eticket-name-subject-xss(39400)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27130" xml:lang="en">27130</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in eTicket 1.5.5.2, and 1.5.6 RC2 and RC3, allow remote attackers to inject arbitrary web script or HTML via the (1) Name and (2) Subject parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:modxcms:modxcms:0.9.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:modxcms:modxcms:0.9.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0094</vuln:cve-id>
    <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-10-11T01:48:31.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T10:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28220" xml:lang="en">28220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39352" xml:lang="en">modx-ajaxsearch-file-include(39352)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27097" xml:lang="en">27097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27096" xml:lang="en">27096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485707/100/0/threaded" xml:lang="en">20080102 MODx CMS Source code disclosure, local file inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://modxcms.com/forums/index.php/topic,21290.0.html" xml:lang="en">http://modxcms.com/forums/index.php/topic,21290.0.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3522" xml:lang="en">3522</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language parameter to assets/snippets/AjaxSearch/AjaxSearch.php, reached through index-ajax.php; and (2) read arbitrary local files via a .. (dot dot) in the file parameter to assets/js/htcmime.php.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_appliance_developer_kit:1.4_revision_95945"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:c.1.0beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisknow:beta_6"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.16"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:s800i:1.0.3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:asterisk:asterisknow:beta_6</vuln:product>
      <vuln:product>cpe:/a:asterisk:s800i:1.0.3.3</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_appliance_developer_kit:1.4_revision_95945</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:c.1.0beta7</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0095</vuln:cve-id>
    <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:56.297-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T10:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27110" xml:lang="en">27110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28312" xml:lang="en">28312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://downloads.digium.com/pub/security/AST-2008-001.html" xml:lang="en">http://downloads.digium.com/pub/security/AST-2008-001.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.digium.com/view.php?id=11637" xml:lang="en">http://bugs.digium.com/view.php?id=11637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00167.html" xml:lang="en">FEDORA-2008-0199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00166.html" xml:lang="en">FEDORA-2008-0198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39361" xml:lang="en">asterisk-bye-also-dos(39361)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0019" xml:lang="en">ADV-2008-0019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019152" xml:lang="en">1019152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485727/100/0/threaded" xml:lang="en">20080102 AST-2008-001: Crash from transfer using BYE with Also header</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28299" xml:lang="en">28299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3520" xml:lang="en">3520</vuln:reference>
    </vuln:references>
    <vuln:summary>The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message with an Also (Also transfer) header, which triggers a NULL pointer dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:georgia_softworks:ssh2_server:7.01.0003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:georgia_softworks:ssh2_server:7.01.0003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0096</vuln:cve-id>
    <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-09-15T01:10:28.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T11:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27103" xml:lang="en">27103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485725/100/0/threaded" xml:lang="en">20080102 Multiple vulnerabilities in Georgia SoftWorks SSH2 Server 7.01.0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28307" xml:lang="en">28307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/gswsshit-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/gswsshit-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3517" xml:lang="en">3517</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:georgia_softworks:ssh2_server:7.01.0003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:georgia_softworks:ssh2_server:7.01.0003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0097</vuln:cve-id>
    <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:12.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T11:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485725/100/0/threaded" xml:lang="en">20080102 Multiple vulnerabilities in Georgia SoftWorks SSH2 Server 7.01.0003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28307" xml:lang="en">28307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/gswsshit-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/gswsshit-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3517" xml:lang="en">3517</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as demonstrated by a certain LoginPassword message.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0098">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:real:realplayer:11_build_6.0.14.748"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:real:realplayer:11_build_6.0.14.748</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0098</vuln:cve-id>
    <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:56.563-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T11:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0016" xml:lang="en">ADV-2008-0016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/current/index.html#public_exploit_code_for_realplayer" xml:lang="en">http://www.us-cert.gov/current/index.html#public_exploit_code_for_realplayer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27091" xml:lang="en">27091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28276" xml:lang="en">28276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.immunitysec.com/pipermail/dailydave/2008-January/004811.html" xml:lang="en">[Dailydave] 20080101 0day RealPlayer exploit demo</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://gleg.net/realplayer11.html" xml:lang="en">http://gleg.net/realplayer11.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019153" xml:lang="en">1019153</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in RealPlayer 11 build 6.0.14.748 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: As of 20080103, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0099">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:myphp_forum:myphp_forum:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:myphp_forum:myphp_forum:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0099</vuln:cve-id>
    <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-09-16T01:14:07.767-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T11:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27118" xml:lang="en">27118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4831" xml:lang="en">4831</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0100">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:white_dune:white_dune:0.29beta791"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:white_dune:white_dune:0.29beta791</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0100</vuln:cve-id>
    <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-10-11T01:48:32.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T11:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27102" xml:lang="en">27102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28287" xml:lang="en">28287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39385" xml:lang="en">whitedune-sceneerrorf-bo(39385)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485724/100/0/threaded" xml:lang="en">20080102 Buffer-overflow and format string in White_Dune 0.29beta791</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://vrml.cip.ica.uni-stuttgart.de/dune/news.html" xml:lang="en">http://vrml.cip.ica.uni-stuttgart.de/dune/news.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/whitedunboffs-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/whitedunboffs-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3516" xml:lang="en">3516</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via a long string in a .WRL file.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0101">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:white_dune:white_dune:0.29beta791"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:white_dune:white_dune:0.29beta791</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0101</vuln:cve-id>
    <vuln:published-datetime>2008-01-07T21:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-10-11T01:48:32.497-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T11:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27102" xml:lang="en">27102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28287" xml:lang="en">28287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39388" xml:lang="en">whitedune-swdegugf-format-string(39388)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485724/100/0/threaded" xml:lang="en">20080102 Buffer-overflow and format string in White_Dune 0.29beta791</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://vrml.cip.ica.uni-stuttgart.de/dune/news.html" xml:lang="en">http://vrml.cip.ica.uni-stuttgart.de/dune/news.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/whitedunboffs-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/whitedunboffs-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3516" xml:lang="en">3516</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the swDebugf function in DuneApp.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a .WRL file.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0102">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:publisher:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher:2002</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0102</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:56.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-13T11:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5305" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5305" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-012.mspx" xml:lang="en">MS08-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0514/references" xml:lang="en">ADV-2008-0514</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019376" xml:lang="en">1019376</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27739" xml:lang="en">27739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28906" xml:lang="en">28906</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">HPSBST02314</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5305" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5305" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0103">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac%2Bos"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac%2Bos</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0103</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T19:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:57.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-13T12:46:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5407" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5407" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-013.mspx" xml:lang="en">MS08-013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0515/references" xml:lang="en">ADV-2008-0515</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019375" xml:lang="en">1019375</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27738" xml:lang="en">27738</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28909" xml:lang="en">28909</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5407" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5407" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka "Microsoft Office Execution Jump Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0104</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:57.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-13T12:13:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:4547" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4547" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0514/references" xml:lang="en">ADV-2008-0514</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-012.mspx" xml:lang="en">MS08-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019377" xml:lang="en">1019377</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27740" xml:lang="en">27740</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28906" xml:lang="en">28906</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:4547" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:4547" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0105">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:works:8.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0105</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:57.237-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-13T12:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5009" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5009" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0513/references" xml:lang="en">ADV-2008-0513</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx" xml:lang="en">MS08-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019387" xml:lang="en">1019387</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27658" xml:lang="en">27658</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28904" xml:lang="en">28904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5009" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5009" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0106">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_engine:1.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server_desktop_engine:2000:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server_express_edition:2005:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server_desktop_engine:2000:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_engine:1.0:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server_express_edition:2005:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0106</vuln:cve-id>
    <vuln:published-datetime>2008-07-08T19:41:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:21:26.047-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-07-09T09:57:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:13785" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13785" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-190A.html" xml:lang="en">TA08-190A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2022/references" xml:lang="en">ADV-2008-2022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1020441" xml:lang="en">1020441</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/494082/100/0/threaded" xml:lang="en">20080708 Re: [Full-disclosure] iDefense Security Advisory 07.08.08: Microsoft SQL Server Restore Integer Underflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx" xml:lang="en">MS08-040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30970" xml:lang="en">30970</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:13785" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:13785" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:7.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2000:sp4:itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server_desktop_engine:2000:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp2:express"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sql_server:2005:sp1:express"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:data_engine:1.0:sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:wmsde:2000"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:wyukon::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:wmsde:2000"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:wyukon::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:wyukon::sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:wyukon::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server_desktop_engine:2000:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp1:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp2:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:wyukon::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp1:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:wmsde:2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_engine:1.0:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp2:express</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp1:express</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:7.0:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp4:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:wyukon::sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2005:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sql_server:2000:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0107</vuln:cve-id>
    <vuln:published-datetime>2008-07-08T19:41:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:21:26.220-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-07-09T10:18:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:13936" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13936" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-190A.html" xml:lang="en">TA08-190A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx" xml:lang="en">MS08-040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2022/references" xml:lang="en">ADV-2008-2022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1020441" xml:lang="en">1020441</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/30119" xml:lang="en">30119</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/494082/100/0/threaded" xml:lang="en">20080708 Re: [Full-disclosure] iDefense Security Advisory 07.08.08: Microsoft SQL Server Restore Integer Underflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.insomniasec.com/advisories/ISVA-080709.1.htm" xml:lang="en">http://www.insomniasec.com/advisories/ISVA-080709.1.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30970" xml:lang="en">30970</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=723" xml:lang="en">20080708 Microsoft SQL Server Restore Integer Underflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:13936" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:13936" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote authenticated users to execute arbitrary code via a (1) SMB or (2) WebDAV pathname for an on-disk file (aka stored backup file) with a crafted record size value, which triggers a heap-based buffer overflow, aka "SQL Server Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:works:8.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0108</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-13T12:20:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5202" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5202" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0513/references" xml:lang="en">ADV-2008-0513</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019388" xml:lang="en">1019388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27659" xml:lang="en">27659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/5107" xml:lang="en">5107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx" xml:lang="en">MS08-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28904" xml:lang="en">28904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=660" xml:lang="en">20080208 Microsoft Office Works Converter Stack-based Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5202" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5202" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:word</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0109</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-10T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-13T12:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5073" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5073" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/692417" xml:lang="en">VU#692417</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-009.mspx" xml:lang="en">MS08-009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0511/references" xml:lang="en">ADV-2008-0511</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019374" xml:lang="en">1019374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27656" xml:lang="en">27656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/488071/100/0/threaded" xml:lang="en">20080213 [Reversemode Advisory] February Advisories : Microsoft Word 2003 + Fortinet Forticlient</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28901" xml:lang="en">28901</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">SSRT080016</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5073" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5073" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0110</vuln:cve-id>
    <vuln:published-datetime>2008-03-11T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:57.767-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-12T11:03:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5278" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5278" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" xml:lang="en">TA08-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/393305" xml:lang="en">VU#393305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28147" xml:lang="en">28147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-015.mspx" xml:lang="en">MS08-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0847/references" xml:lang="en">ADV-2008-0847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019579" xml:lang="en">1019579</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29320" xml:lang="en">29320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5278" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5278" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0111</vuln:cve-id>
    <vuln:published-datetime>2008-03-11T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:57.877-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-12T11:27:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5114" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5114" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" xml:lang="en">TA08-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28094" xml:lang="en">28094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" xml:lang="en">MS08-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0846/references" xml:lang="en">ADV-2008-0846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019582" xml:lang="en">1019582</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">SSRT080028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5114" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5114" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka "Excel Data Validation Record Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2008::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2008::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0112</vuln:cve-id>
    <vuln:published-datetime>2008-03-11T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:57.953-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-12T12:37:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5284" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5284" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" xml:lang="en">TA08-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28095" xml:lang="en">28095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" xml:lang="en">MS08-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0846/references" xml:lang="en">ADV-2008-0846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019583" xml:lang="en">1019583</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">SSRT080028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5284" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5284" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka "Excel File Import Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0113</vuln:cve-id>
    <vuln:published-datetime>2008-03-11T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-12T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-12T12:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5421" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5421" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" xml:lang="en">TA08-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-016.mspx" xml:lang="en">MS08-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-08-008" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-08-008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0848/references" xml:lang="en">ADV-2008-0848</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019578" xml:lang="en">1019578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/489415/100/0/threaded" xml:lang="en">20080311 ZDI-08-008: Microsoft Excel BIFF File Format Cell Record Parsing Memory Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29321" xml:lang="en">29321</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5421" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5421" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0114</vuln:cve-id>
    <vuln:published-datetime>2008-03-11T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:58.157-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-12T12:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5456" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5456" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" xml:lang="en">TA08-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28166" xml:lang="en">28166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" xml:lang="en">MS08-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0846/references" xml:lang="en">ADV-2008-0846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019584" xml:lang="en">1019584</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5456" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5456" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0115</vuln:cve-id>
    <vuln:published-datetime>2008-03-11T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:58.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-12T12:54:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5512" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5512" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" xml:lang="en">TA08-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28167" xml:lang="en">28167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" xml:lang="en">MS08-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0846/references" xml:lang="en">ADV-2008-0846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019585" xml:lang="en">1019585</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5512" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5512" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka "Excel Formula Parsing Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0116">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2008::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2008::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0116</vuln:cve-id>
    <vuln:published-datetime>2008-03-11T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-18T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-12T12:56:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5212" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5212" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" xml:lang="en">TA08-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28168" xml:lang="en">28168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" xml:lang="en">MS08-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0846/references" xml:lang="en">ADV-2008-0846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019586" xml:lang="en">1019586</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/489430/100/0/threaded" xml:lang="en">20080311 TPTI-08-03: Microsoft Excel Rich Text Memory Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://dvlabs.tippingpoint.com/advisory/TPTI-08-03" xml:lang="en">http://dvlabs.tippingpoint.com/advisory/TPTI-08-03</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5212" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5212" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0117">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:compatibility_pack_word_excel_powerpoint_2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2008::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:compatibility_pack_word_excel_powerpoint_2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2008::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0117</vuln:cve-id>
    <vuln:published-datetime>2008-03-11T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:58.437-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-12T13:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5508" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5508" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" xml:lang="en">TA08-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28170" xml:lang="en">28170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" xml:lang="en">MS08-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0846/references" xml:lang="en">ADV-2008-0846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019587" xml:lang="en">1019587</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">SSRT080028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5508" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5508" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka "Excel Conditional Formatting Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0118</vuln:cve-id>
    <vuln:published-datetime>2008-03-11T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:58.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-12T13:32:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5190" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5190" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" xml:lang="en">TA08-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28146" xml:lang="en">28146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-016.mspx" xml:lang="en">MS08-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0848/references" xml:lang="en">ADV-2008-0848</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019578" xml:lang="en">1019578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29321" xml:lang="en">29321</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">HPSBST02320</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5190" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5190" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007_sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2007_sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0119</vuln:cve-id>
    <vuln:published-datetime>2008-05-13T18:20:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:58.597-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-05-13T20:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5303" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5303" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-134A.html" xml:lang="en">TA08-134A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-027.mspx" xml:lang="en">MS08-027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1505/references" xml:lang="en">ADV-2008-1505</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1020015" xml:lang="en">1020015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/29158" xml:lang="en">29158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/492073/100/0/threaded" xml:lang="en">20080514 Microsoft Office Publisher PUB File Parsing Remote Memory Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30150" xml:lang="en">30150</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121129490723574&amp;w=2" xml:lang="en">HPSBST02336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121129490723574&amp;w=2" xml:lang="en">HPSBST02336</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5303" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5303" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_powerpoint_viewer:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office_powerpoint_viewer:2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0120</vuln:cve-id>
    <vuln:published-datetime>2008-08-12T20:41:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:58.703-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-08-13T10:59:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5768" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5768" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-225A.html" xml:lang="en">TA08-225A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-051.mspx" xml:lang="en">MS08-051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31453" xml:lang="en">31453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2355" xml:lang="en">ADV-2008-2355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1020676" xml:lang="en">1020676</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/30552" xml:lang="en">30552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121915960406986&amp;w=2" xml:lang="en">SSRT080117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121915960406986&amp;w=2" xml:lang="en">SSRT080117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=739" xml:lang="en">20080812 Microsoft PowerPoint Viewer 2003 Cstring Integer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5768" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5768" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0121">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_powerpoint_viewer:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office_powerpoint_viewer:2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0121</vuln:cve-id>
    <vuln:published-datetime>2008-08-12T20:41:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:58.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-08-13T11:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5724" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5724" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-225A.html" xml:lang="en">TA08-225A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2355" xml:lang="en">ADV-2008-2355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1020676" xml:lang="en">1020676</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/30554" xml:lang="en">30554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms08-051.mspx" xml:lang="en">MS08-051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31453" xml:lang="en">31453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121915960406986&amp;w=2" xml:lang="en">HPSBST02360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121915960406986&amp;w=2" xml:lang="en">HPSBST02360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=738" xml:lang="en">20080812 Microsoft PowerPoint Viewer 2003 Out of Bounds Array Index Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5724" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5724" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2008-0122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2"/>
          <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.3"/>
          <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:7.0:pre-release"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:bind:9.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0122</vuln:cve-id>
    <vuln:published-datetime>2008-01-15T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-30T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-16T12:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10190" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10190" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/203611" xml:lang="en">VU#203611</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27283" xml:lang="en">27283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://security.freebsd.org/advisories/FreeBSD-SA-08:02.libc.asc" xml:lang="en">FreeBSD-SA-08:02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00782.html" xml:lang="en">FEDORA-2008-0904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00781.html" xml:lang="en">FEDORA-2008-0903</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-2169" xml:lang="en">https://issues.rpath.com/browse/RPL-2169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=429149" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=429149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39670" xml:lang="en">freebsd-inetnetwork-bo(39670)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4167" xml:lang="en">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&amp;heading=AIX61&amp;path=/200802/SECURITY/20080227/datafile123640&amp;label=AIX%20libc%20inet_network%20buffer%20overflow" xml:lang="en">http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&amp;heading=AIX61&amp;path=/200802/SECURITY/20080227/datafile123640&amp;label=AIX%20libc%20inet_network%20buffer%20overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1743/references" xml:lang="en">ADV-2008-1743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0703" xml:lang="en">ADV-2008-0703</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0193" xml:lang="en">ADV-2008-0193</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019189" xml:lang="en">1019189</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487000/100/0/threaded" xml:lang="en">20080124 rPSA-2008-0029-1 bind bind-utils</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0300.html" xml:lang="en">RHSA-2008:0300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.isc.org/index.pl?/sw/bind/bind-security.php" xml:lang="en">http://www.isc.org/index.pl?/sw/bind/bind-security.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2008-244.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2008-244.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238493-1" xml:lang="en">238493</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30718" xml:lang="en">30718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30538" xml:lang="en">30538</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30313" xml:lang="en">30313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29323" xml:lang="en">29323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29161" xml:lang="en">29161</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28579" xml:lang="en">28579</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28487" xml:lang="en">28487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28429" xml:lang="en">28429</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28367" xml:lang="en">28367</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html" xml:lang="en">SUSE-SR:2008:006</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10190" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10190" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:moodle:moodle:1.8.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:moodle:moodle:1.8.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0123</vuln:cve-id>
    <vuln:published-datetime>2008-01-11T20:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:59.047-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-14T09:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0164" xml:lang="en">ADV-2008-0164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://int21.de/cve/CVE-2008-0123-moodle.html" xml:lang="en">http://int21.de/cve/CVE-2008-0123-moodle.html </vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0202.html" xml:lang="en">20080111 Cross site scripting (XSS) in Moodle 1.8.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39630" xml:lang="en">moodle-install-xss(39630)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27259" xml:lang="en">27259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/486198/100/0/threaded" xml:lang="en">20080111 Cross site scripting (XSS) in Moodle 1.8.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28838" xml:lang="en">28838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html" xml:lang="en">SUSE-SR:2008:003</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter.  NOTE: this issue only exists until the installation is complete.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.5_pl1"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.6_pl1"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.6_pl2"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.6_pl3"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.6_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.6_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.7_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.7_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.7_beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.7_beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.7_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.8_beta_6_snapshot"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.8_beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.8_beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:1.0_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:1.0_beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:s9y:serendipity:1.2__beta5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:s9y:serendipity:0.8_beta_6_snapshot</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:1.0_beta3</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.7_beta4</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.8.2</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.6</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.3</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:1.1.1</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.7_beta2</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:1.2.1</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.5_pl1</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.9.1</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:1.0_beta2</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.8.1</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:1.0.4</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.8</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:1.1.4</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:1.2__beta5</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.8_beta5</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.7_beta1</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:1.1.3</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.7.1</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.6_pl3</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.6_pl2</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.7_rc1</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.8_beta6</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.7_beta3</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:1.2</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.6_rc1</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:1.0.3</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.6_rc2</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.4</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.6_pl1</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.5</vuln:product>
      <vuln:product>cpe:/a:s9y:serendipity:0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0124</vuln:cve-id>
    <vuln:published-datetime>2008-02-28T15:44:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:59.143-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-29T09:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://blog.s9y.org/archives/191-Serendipity-1.3-beta1-released.html" xml:lang="en">http://blog.s9y.org/archives/191-Serendipity-1.3-beta1-released.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/40851" xml:lang="en">serendipity-realname-username-xss(40851)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0700/references" xml:lang="en">ADV-2008-0700</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019502" xml:lang="en">1019502</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28003" xml:lang="en">28003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1528" xml:lang="en">DSA-1528</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29502" xml:lang="en">29502</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29128" xml:lang="en">29128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://int21.de/cve/CVE-2008-0124-s9y.html" xml:lang="en">http://int21.de/cve/CVE-2008-0124-s9y.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3-beta1 allows remote authenticated users to inject arbitrary web script or HTML via (1) the "Real name" field in Personal Settings, which is presented to readers of articles; or (2) a file upload, as demonstrated by a .htm, .html, or .js file.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpstats:phpstats:0.1_alpha"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpstats:phpstats:0.1_alpha</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0125</vuln:cve-id>
    <vuln:published-datetime>2008-03-24T18:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-10-11T01:48:35.120-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-25T10:50:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41261" xml:lang="en">phpstats-phpstats-xss(41261)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28291" xml:lang="en">28291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/489722/100/0/threaded" xml:lang="en">20080317 Cross Site Scripting (XSS) in phpstats 0.1_alpha, CVE-2008-0125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3765" xml:lang="en">3765</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in phpstats.php in Michael Wagner phpstats 0.1 alpha allows remote attackers to inject arbitrary web script or HTML via the baseDir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:e-business_server:8.5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:e-business_server:8.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0127</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:59.377-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T11:17:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27197" xml:lang="en">27197</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/486035/100/0/threaded" xml:lang="en">20080109 [INFIGO-2008-01-06]: McAfee E-Business Server Remote Preauth Code Execution / DoS - Corrected</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485992/100/0/threaded" xml:lang="en">20080109 [INFIGO 2008-01-06]: McAfee E-Business Server Remote Preauth Code Execution / DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=614472&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=614472" xml:lang="en">https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=614472&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=614472</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39563" xml:lang="en">mcafee-ebusiness-packet-code-execution(39563)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39561" xml:lang="en">mcafee-ebusiness-authentication-packet-dos(39561)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0087" xml:lang="en">ADV-2008-0087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4878" xml:lang="en">4878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019170" xml:lang="en">1019170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3530" xml:lang="en">3530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28408" xml:lang="en">28408</vuln:reference>
    </vuln:references>
    <vuln:summary>The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long initial authentication packet.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0128">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:5.5.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0128</vuln:cve-id>
    <vuln:published-datetime>2008-01-22T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:03:59.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-23T10:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://issues.apache.org/bugzilla/show_bug.cgi?id=41217" xml:lang="en">http://issues.apache.org/bugzilla/show_bug.cgi?id=41217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39804" xml:lang="en">apache-singlesignon-information-disclosure(39804)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0233" xml:lang="en">ADV-2009-0233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0192" xml:lang="en">ADV-2008-0192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27365" xml:lang="en">27365</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/500412/100/0/threaded" xml:lang="en">20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/500396/100/0/threaded" xml:lang="en">20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540" xml:lang="en">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://security-tracker.debian.net/tracker/CVE-2008-0128" xml:lang="en">http://security-tracker.debian.net/tracker/CVE-2008-0128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33668" xml:lang="en">33668</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31493" xml:lang="en">31493</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28552" xml:lang="en">28552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28549" xml:lang="en">28549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2008-0630.html" xml:lang="en">RHSA-2008:0630</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx" xml:lang="en">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0261.html" xml:lang="en">RHSA-2008:0261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29242" xml:lang="en">29242</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html" xml:lang="en">SUSE-SR:2008:005</vuln:reference>
    </vuln:references>
    <vuln:summary>The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:siteatschool:siteatschool:2.3.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:siteatschool:siteatschool:2.3.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0129</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T06:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:17.343-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T11:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4832" xml:lang="en">4832</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39417" xml:lang="en">siteatschool-slideshowfull-sql-injection(39417)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27120" xml:lang="en">27120</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0130">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:instantsoftwares:dating_site"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:instantsoftwares:dating_site</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0130</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T06:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-05T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T11:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39326" xml:lang="en">dating-site-login-sql-injection(39326)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39326" xml:lang="en">dating-site-login-sql-injection(39326)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28283" xml:lang="en">28283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/39766" xml:lang="en">39766</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Username parameter, a different vulnerability than CVE-2007-6671.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:instantsoftwares:dating_site"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:instantsoftwares:dating_site</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0131</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T06:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-09-15T01:10:32.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T11:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27121" xml:lang="en">27121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28283" xml:lang="en">28283</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different product than CVE-2006-6022.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0132">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pragma_systems:fortressssh:5.0_build_4_r_293"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pragma_systems:fortressssh:5.0_build_4_r_293</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0132</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T06:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:17.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T11:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39354" xml:lang="en">fortressssh-sshd-dos(39354)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.org/poc/pragmassh.zip" xml:lang="en">http://aluigi.org/poc/pragmassh.zip</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/pragmassh-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/pragmassh-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27141" xml:lang="en">27141</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=119947184730448&amp;w=2" xml:lang="en">20080104 Some DoS in some telnet servers</vuln:reference>
    </vuln:references>
    <vuln:summary>Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the administrator to click in this window before terminating the sshd.exe process, which allows remote attackers to cause a denial of service (connection slot exhaustion) via a flood of SSH connections with long data objects, as demonstrated by (1) a long list of keys and (2) a long username.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:thomas_perez:tribisur:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:thomas_perez:tribisur:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0133</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:17.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T15:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27149" xml:lang="en">27149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4840" xml:lang="en">4840</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28362" xml:lang="en">28362</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39443" xml:lang="en">tribisur-catmain-forum-sql-injection(39443)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.04"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.03"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.02"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.03"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.01"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.02"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.2.03"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.1:sr4"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.05"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.06"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.1:sr4</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.02</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.05</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.03</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.1</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.01</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.0</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.04</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.02</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.06</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.2.03</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0134</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-24T12:34:56.597-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T15:07:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27162" xml:lang="en">27162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded" xml:lang="en">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt" xml:lang="en">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28284" xml:lang="en">28284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://hackerscenter.com/archive/view.asp?id=28145" xml:lang="en">http://hackerscenter.com/archive/view.asp?id=28145</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.04"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.03"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.02"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.03"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.01"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.02"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.2.03"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.1:sr4"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.05"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.06"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.1:sr4</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.02</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.05</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.03</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.1</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.01</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.0</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.04</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.02</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.06</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.2.03</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0135</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-24T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T15:16:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485894/100/200/threaded" xml:lang="en">20080107 RE: [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded" xml:lang="en">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt" xml:lang="en">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://hackerscenter.com/archive/view.asp?id=28145" xml:lang="en">http://hackerscenter.com/archive/view.asp?id=28145</vuln:reference>
    </vuln:references>
    <vuln:summary>Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum/snitz_forums_2000.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.05"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.05</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0136</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-24T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-08T15:18:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485894/100/200/threaded" xml:lang="en">20080107 RE: [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded" xml:lang="en">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt" xml:lang="en">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://hackerscenter.com/archive/view.asp?id=28145" xml:lang="en">http://hackerscenter.com/archive/view.asp?id=28145</vuln:reference>
    </vuln:references>
    <vuln:summary>Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:snetworks:php_classifieds:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snetworks:php_classifieds:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0137</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:00.360-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T10:23:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0053" xml:lang="en">ADV-2008-0053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4838" xml:lang="en">4838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39468" xml:lang="en">snetworks-configinc-file-include(39468)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xoops:xoopsgallery_module:1.3.3_9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xoops:xoopsgallery_module:1.3.3_9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0138</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:18.670-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T10:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39461" xml:lang="en">xoops-modgallery-zendhashkey-file-include(39461)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27155" xml:lang="en">27155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4847" xml:lang="en">4847</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:loudblog:loudblog:0.8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:loudblog:loudblog:0.8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0139</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:18.810-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T10:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27157" xml:lang="en">27157</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28336" xml:lang="en">28336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/4849" xml:lang="en">4849</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39445" xml:lang="en">loudblog-template-code-execution(39445)</vuln:reference>
    </vuln:references>
    <vuln:summary>Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0140">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:uebimiau:webmail:2.7.10"/>
        <cpe-lang:fact-ref name="cpe:/a:uebimiau:webmail:2.7.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:uebimiau:webmail:2.7.2</vuln:product>
      <vuln:product>cpe:/a:uebimiau:webmail:2.7.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0140</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-10-22T01:44:05.437-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T10:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39460" xml:lang="en">uebimiau-webmail-error-directory-traversal(39460)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27154" xml:lang="en">27154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4846" xml:lang="en">4846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2008-January/001867.html" xml:lang="en">20080107 Uebimiau Web-Mail 2.7.10/2.7.2 Remote File Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the selected_theme parameter, a different vector than CVE-2007-3172.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:webportal:webportal_cms:0.6_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webportal:webportal_cms:0.6_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0141</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:19.123-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T10:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27145" xml:lang="en">27145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4835" xml:lang="en">4835</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39486" xml:lang="en">webportal-action-weak-security(39486)</vuln:reference>
    </vuln:references>
    <vuln:summary>actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:webportal:webportal_cms:0.6_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webportal:webportal_cms:0.6_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0142</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:19.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T10:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4835" xml:lang="en">4835</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecified other vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:spacial_audio_solutions:sam_broadcaster"/>
        <cpe-lang:fact-ref name="cpe:/a:spacial_audio_solutions:samphpweb"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:spacial_audio_solutions:sam_broadcaster</vuln:product>
      <vuln:product>cpe:/a:spacial_audio_solutions:samphpweb</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0143</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:19.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T10:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39397" xml:lang="en">samPHPweb-db-file-include(39397)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.spacialaudio.com/news/index.html" xml:lang="en">http://www.spacialaudio.com/news/index.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27137" xml:lang="en">27137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4834" xml:lang="en">4834</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28355" xml:lang="en">28355</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM Broadcaster, allows remote attackers to execute arbitrary PHP code via a URL in the commonpath parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0144">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phprisk:netrisk:1.9.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phprisk:netrisk:1.9.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0144</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-09-15T01:10:34.750-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T11:05:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39419" xml:lang="en">netrisk-index-file-include(39419)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27136" xml:lang="en">27136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4833" xml:lang="en">4833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28328" xml:lang="en">28328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=119955114428283&amp;w=2" xml:lang="en">20080105 NetRisk 1.9.7 Remote File Inclusion Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.  NOTE: this can also be leveraged for local file inclusion using directory traversal sequences.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.4.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0145</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-09-16T01:14:13.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T11:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39401" xml:lang="en">php-glob-openbasedir-security-bypass(39401)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0059" xml:lang="en">ADV-2008-0059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/releases/4_4_8.php" xml:lang="en">http://www.php.net/releases/4_4_8.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-4.php" xml:lang="en">http://www.php.net/ChangeLog-4.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28318" xml:lang="en">28318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.php.net/bug.php?id=41655" xml:lang="en">http://bugs.php.net/bug.php?id=41655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.335136" xml:lang="en">SSA:2008-045-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28936" xml:lang="en">28936</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors.  NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0146">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hughes_technologies:w3-msql"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hughes_technologies:w3-msql</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0146</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T14:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-09-15T01:10:34.953-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T11:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27116" xml:lang="en">27116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485736/100/0/threaded" xml:lang="en">20080103 xss in w3-msql error page</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28294" xml:lang="en">28294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51235" xml:lang="en">51235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3521" xml:lang="en">3521</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the top-level URI.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0147">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:smallnuke:smallnuke:2.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:smallnuke:smallnuke:2.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0147</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:20.013-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T13:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27180" xml:lang="en">27180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4863" xml:lang="en">4863</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28301" xml:lang="en">28301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39525" xml:lang="en">smallnuke-index-sql-injection(39525)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0148">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tutos:tutos:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tutos:tutos:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0148</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:20.153-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T13:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28291" xml:lang="en">28291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/4861" xml:lang="en">4861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39531" xml:lang="en">tutos-cmd-command-execution(39531)</vuln:reference>
    </vuln:references>
    <vuln:summary>TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0149">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tutos:tutos:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tutos:tutos:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0149</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:20.310-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T13:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28291" xml:lang="en">28291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/4861" xml:lang="en">4861</vuln:reference>
    </vuln:references>
    <vuln:summary>TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0150">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:aruba_networks:aruba_mobility_controllers:2.3.6.15"/>
        <cpe-lang:fact-ref name="cpe:/a:aruba_networks:aruba_mobility_controllers:2.5.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:aruba_networks:aruba_mobility_controllers:2.5.4.25"/>
        <cpe-lang:fact-ref name="cpe:/a:aruba_networks:aruba_mobility_controllers:2.5.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:aruba_networks:aruba_mobility_controllers:3.1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:aruba_networks:aruba_mobility_controllers:2.4.8.11-fips"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aruba_networks:aruba_mobility_controllers:2.5.4.25</vuln:product>
      <vuln:product>cpe:/a:aruba_networks:aruba_mobility_controllers:2.5.2.11</vuln:product>
      <vuln:product>cpe:/a:aruba_networks:aruba_mobility_controllers:2.3.6.15</vuln:product>
      <vuln:product>cpe:/a:aruba_networks:aruba_mobility_controllers:2.4.8.11-fips</vuln:product>
      <vuln:product>cpe:/a:aruba_networks:aruba_mobility_controllers:2.5.5.7</vuln:product>
      <vuln:product>cpe:/a:aruba_networks:aruba_mobility_controllers:3.1.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0150</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:20.450-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T13:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27144" xml:lang="en">27144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485831/100/0/threaded" xml:lang="en">20080104 Aruba Mobility Controller User Authentication Vulnerability - Aruba Advisory ID: AID-122207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.arubanetworks.com/support/alerts/aid-122207.asc" xml:lang="en">http://www.arubanetworks.com/support/alerts/aid-122207.asc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28357" xml:lang="en">28357</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3529" xml:lang="en">3529</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the LDAP authentication feature in Aruba Mobility Controller 2.3.6.15, 2.5.2.11, 2.5.4.25, 2.5.5.7, 3.1.1.3, and 2.4.8.11-FIPS or earlier allows remote attackers to bypass authentication mechanisms and obtain management or VPN interface access.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0151">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:foxitsoftware:wac_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:foxitsoftware:wac_server:2.1.0.910"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:foxitsoftware:wac_server:2.1.0.910</vuln:product>
      <vuln:product>cpe:/a:foxitsoftware:wac_server:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0151</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-08-25T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T14:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39427" xml:lang="en">wacserver-option-dos(39427)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27142" xml:lang="en">27142</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/488366/100/200/threaded" xml:lang="en">20080219 Two heap overflow in Foxit WAC Server 2.0 Build 3503</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485812/100/0/threaded" xml:lang="en">20080104 Some DoS in some telnet servers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3525" xml:lang="en">3525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28272" xml:lang="en">28272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/wachof-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/wachof-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/waccaz-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/waccaz-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Telnet request with long options.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0152">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:seattle_lab_software:slnet_rf_telnet_server:4.1.1.3758"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:seattle_lab_software:slnet_rf_telnet_server:4.1.1.3758</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0152</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T14:16:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27134" xml:lang="en">27134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28316" xml:lang="en">28316</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=119947184730448&amp;w=2" xml:lang="en">20080104 Some DoS in some telnet servers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/slnetmsg-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/slnetmsg-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>SLnet.exe in SeattleLab SLNet RF Telnet Server 4.1.1.3758 and earlier allows user-assisted remote attackers to cause a denial of service (crash) via unspecified telnet options, which triggers a NULL pointer dereference.  NOTE: the crash is not user-assisted when the server is running in debug mode.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0153">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pragma_systems:pragma_telnetserver:7.0.4.589"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pragma_systems:pragma_telnetserver:7.0.4.589</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0153</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-10-11T01:48:37.560-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T14:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39353" xml:lang="en">pragmatelnetserver-telnetd-dos(39353)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27143" xml:lang="en">27143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=119947184730448&amp;w=2" xml:lang="en">20080104 Some DoS in some telnet servers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/pragmatel-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/pragmatel-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafted TELOPT PRAGMA LOGON telnet option, which triggers a NULL pointer dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0154">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:evilboard:evilboard:0.1a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:evilboard:evilboard:0.1a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0154</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-09-15T01:10:35.703-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T14:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39529" xml:lang="en">evilboard-index-sql-injection(39529)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27190" xml:lang="en">27190</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4865" xml:lang="en">4865</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:evilboard:evilboard:0.1a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:evilboard:evilboard:0.1a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0155</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-09-15T01:10:35.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T14:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27190" xml:lang="en">27190</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4865" xml:lang="en">4865</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39526" xml:lang="en">evilboard-index-xss(39526)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the c parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:million_dollar_script:million_dollar_script:2.0.14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:million_dollar_script:million_dollar_script:2.0.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0156</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:21.343-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T14:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39492" xml:lang="en">milliondollarscript-index-dir-traversal(39492)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27174" xml:lang="en">27174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485882/100/0/threaded" xml:lang="en">20080107 Million Dollar Script 2.0.14 Remote File Disclosure Vulnerability.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3524" xml:lang="en">3524</vuln:reference>
    </vuln:references>
    <vuln:summary>Absolute path traversal vulnerability in index.php in Million Dollar Script 2.0.14 allows remote attackers to read arbitrary files via encoded "/" (%2F) sequences in the link parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0157">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:flexbb:flexbb:1.0_10005_beta_release_1"/>
        <cpe-lang:fact-ref name="cpe:/a:flexbb:flexbb:0.6.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:flexbb:flexbb:0.6.3</vuln:product>
      <vuln:product>cpe:/a:flexbb:flexbb:1.0_10005_beta_release_1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0157</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:21.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T14:31:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39475" xml:lang="en">flexbb-flexbbtempid-sql-injection(39475)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27164" xml:lang="en">27164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4858" xml:lang="en">4858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28373" xml:lang="en">28373</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0158">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:shop-script:shop-script:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:shop-script:shop-script:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0158</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:21.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T14:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39449" xml:lang="en">shopscript-index-directory-traversal(39449)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27165" xml:lang="en">27165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.org/0801-exploits/shopscript-disclose.txt" xml:lang="en">http://packetstormsecurity.org/0801-exploits/shopscript-disclose.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4855" xml:lang="en">4855</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a .. (dot dot) in the aux_page parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0159">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eggblog:eggblog:3.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eggblog:eggblog:3.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0159</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:21.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-09T14:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39473" xml:lang="en">eggblog-eggblogmail-sql-injection(39473)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27168" xml:lang="en">27168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4860" xml:lang="en">4860</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28371" xml:lang="en">28371</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::alpha"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::amd64"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::arm"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::hppa"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::ia-32"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::ia-64"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::m68k"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::mips"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::mipsel"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::powerpc"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::s-390"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::sparc"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:sam_lantinga:splitvt:1.6.6"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sam_lantinga:splitvt:1.6.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0162</vuln:cve-id>
    <vuln:published-datetime>2008-02-22T16:44:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:21.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-25T09:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1500" xml:lang="en">DSA-1500</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27936" xml:lang="en">27936</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29080" xml:lang="en">29080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29064" xml:lang="en">29064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200803-05.xml" xml:lang="en">GLSA-200803-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29190" xml:lang="en">29190</vuln:reference>
    </vuln:references>
    <vuln:summary>misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0163">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0163</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T16:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:22.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T17:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-59"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1494" xml:lang="en">DSA-1494</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/40486" xml:lang="en">linux-kernel-proc-unauth-access(40486)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27798" xml:lang="en">27798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27704" xml:lang="en">27704</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28875" xml:lang="en">28875</vuln:reference>
    </vuln:references>
    <vuln:summary>Linux kernel 2.6, when using vservers, allows local users to access resources of other vservers via a symlink attack in /proc.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0164">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:plone:plone_cms:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:plone:plone_cms:3.0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:plone:plone_cms:3.0.5</vuln:product>
      <vuln:product>cpe:/a:plone:plone_cms:3.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0164</vuln:cve-id>
    <vuln:published-datetime>2008-03-19T20:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:22.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-03-20T10:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/489544/100/0/threaded" xml:lang="en">20080313 PR08-02: Plone CMS Security Research - the Art of Plowning</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.procheckup.com/Hacking_Plone_CMS.pdf" xml:lang="en">http://www.procheckup.com/Hacking_Plone_CMS.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29361" xml:lang="en">29361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://plone.org/about/security/advisories/cve-2008-0164" xml:lang="en">http://plone.org/about/security/advisories/cve-2008-0164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41263" xml:lang="en">plone-joinform-csrf(41263)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3754" xml:lang="en">3754</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote attackers to (1) add arbitrary accounts via the join_form page and (2) change the privileges of arbitrary groups via the prefs_groups_overview page.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0165">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.41"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.41</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0165</vuln:cve-id>
    <vuln:published-datetime>2008-04-21T09:05:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:03.080-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-04-21T14:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41904" xml:lang="en">ikiwiki-change-password-csrf(41904)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1297/references" xml:lang="en">ADV-2008-1297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1553" xml:lang="en">DSA-1553</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29932" xml:lang="en">29932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29907" xml:lang="en">29907</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ikiwiki.info/security/#index31h2" xml:lang="en">http://ikiwiki.info/security/#index31h2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475445" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475445</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0166">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8c-1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8c-2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8c-3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8c-4"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8c-5"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8c-6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8c-7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8c-8"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8c-9"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8d-1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8d-2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8d-3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8d-4"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8d-5"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8d-6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8d-7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8d-8"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8d-9"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8e-1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8e-2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8e-3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8e-4"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8e-5"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8e-6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8e-7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8e-8"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8e-9"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8f-1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8f-2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8f-3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8f-4"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8f-5"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8f-6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8f-7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8f-8"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8f-9"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8g-1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8g-2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8g-3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8g-4"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8g-5"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8g-6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8g-7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8g-8"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl_project:openssl:0.9.8g-9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8d-9</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8c-1</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8d-4</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8c-9</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8f-4</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8c-7</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8e-3</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8e-6</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8g-1</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8f-3</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8c-4</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8d-7</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8e-5</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8c-2</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8f-2</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8g-7</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8g-2</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8d-5</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8f-1</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8g-6</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8g-4</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8d-2</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8f-6</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8d-3</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8c-6</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8d-6</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8f-5</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8c-8</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8e-2</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8f-7</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8e-4</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8f-8</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8g-3</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8e-8</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8d-1</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8e-9</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8e-1</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8e-7</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8c-5</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8d-8</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8f-9</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8c-3</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8g-8</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8g-5</vuln:product>
      <vuln:product>cpe:/a:openssl_project:openssl:0.9.8g-9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0166</vuln:cve-id>
    <vuln:published-datetime>2008-05-13T13:20:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-02-21T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-05-13T14:25:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-137A.html" xml:lang="en">TA08-137A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/925211" xml:lang="en">VU#925211</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-612-2" xml:lang="en">USN-612-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-612-1" xml:lang="en">USN-612-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1576" xml:lang="en">DSA-1576</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1571" xml:lang="en">DSA-1571</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/42375" xml:lang="en">openssl-rng-weak-security(42375)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-612-7" xml:lang="en">USN-612-7</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-612-4" xml:lang="en">USN-612-4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-612-3" xml:lang="en">USN-612-3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1020017" xml:lang="en">1020017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/29179" xml:lang="en">29179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/492112/100/0/threaded" xml:lang="en">20080515 Debian generated SSH-Keys working exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/5720" xml:lang="en">5720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/5632" xml:lang="en">5632</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/5622" xml:lang="en">5622</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://sourceforge.net/mailarchive/forum.php?thread_name=48367252.7070603%40shemesh.biz&amp;forum_name=rsyncrypto-devel" xml:lang="en">[rsyncrypto-devel] 20080523 Advisory - Rsyncrypto maybe affected from Debian OpenSSL reduced entropy problem</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30249" xml:lang="en">30249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30239" xml:lang="en">30239</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30231" xml:lang="en">30231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30221" xml:lang="en">30221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30220" xml:lang="en">30220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30136" xml:lang="en">30136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://metasploit.com/users/hdm/tools/debian-openssl/" xml:lang="en">http://metasploit.com/users/hdm/tools/debian-openssl/</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0167">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::alpha"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::amd64"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::arm"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::hppa"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::ia-32"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::ia-64"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::m68k"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::mips"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::mipsel"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::powerpc"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::s390"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::sparc"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:gforge:gforge:4.5.14"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gforge:gforge:4.5.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0167</vuln:cve-id>
    <vuln:published-datetime>2008-05-18T10:20:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:04.047-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-05-19T09:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-59"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1577" xml:lang="en">DSA-1577</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/42456" xml:lang="en">gforge-unspecified-symlink(42456)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1537/references" xml:lang="en">ADV-2008-1537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/29215" xml:lang="en">29215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch8.diff.gz" xml:lang="en">http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch8.diff.gz</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30286" xml:lang="en">30286</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30088" xml:lang="en">30088</vuln:reference>
    </vuln:references>
    <vuln:summary>The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0169">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.34"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.34.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.34.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.35"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.36"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.37"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.38"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.39"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.40"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.41"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.42"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.43"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.44"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.45"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.46"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.47"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.48"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.49"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:1.51"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.13"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.18"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.19"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.20"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.30"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.31"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.31.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.31.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.31.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.40"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.41"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.42"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.43"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.44"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.47"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ikiwiki:ikiwiki:2.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.39</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.38</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.18</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.7</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.6</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.14</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.20</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.5</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.37</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.34.1</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.31.3</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.34.2</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.34</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.31.1</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.3</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.46</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.1</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.35</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.43</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.42</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.15</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.5</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.8</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.9</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.17</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.43</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.2</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.31.2</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.19</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.0</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.40</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.16</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.44</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.48</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.41</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.41</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.47</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.30</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.49</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.36</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.11</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.47</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.12</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.31</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.40</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.51</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.45</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:1.42</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.13</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.44</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.4</vuln:product>
      <vuln:product>cpe:/a:ikiwiki:ikiwiki:2.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0169</vuln:cve-id>
    <vuln:published-datetime>2008-06-03T11:32:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:04.143-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-06-03T15:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/42798" xml:lang="en">ikiwiki-openid-passwordauth-auth-bypass(42798)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1710" xml:lang="en">ADV-2008-1710</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/29479" xml:lang="en">29479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2008/05/31/3" xml:lang="en">[oss-security] 20080531 Re: CVE id request: ikiwiki</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30468" xml:lang="en">30468</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ikiwiki.info/security/#index33h2" xml:lang="en">http://ikiwiki.info/security/#index33h2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ikiwiki.info/news/version_2.48/index.html" xml:lang="en">http://ikiwiki.info/news/version_2.48/index.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=483770" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=483770</vuln:reference>
    </vuln:references>
    <vuln:summary>Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID identity is configured and a password is not configured, by specifying an empty password during the login sequence.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0171">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:boost:boost:1.33"/>
        <cpe-lang:fact-ref name="cpe:/a:boost:boost:1.34"/>
        <cpe-lang:fact-ref name="cpe:/a:boost:boost_regex_library"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:boost:boost_regex_library</vuln:product>
      <vuln:product>cpe:/a:boost:boost:1.33</vuln:product>
      <vuln:product>cpe:/a:boost:boost:1.34</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0171</vuln:cve-id>
    <vuln:published-datetime>2008-01-17T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:04.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-18T09:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-2143" xml:lang="en">https://issues.rpath.com/browse/RPL-2143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0249" xml:lang="en">ADV-2008-0249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-570-1" xml:lang="en">USN-570-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27325" xml:lang="en">27325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.boost.org/trac/boost/changeset/42745" xml:lang="en">http://svn.boost.org/trac/boost/changeset/42745</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.boost.org/trac/boost/changeset/42674" xml:lang="en">http://svn.boost.org/trac/boost/changeset/42674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=205955" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=205955</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html" xml:lang="en">FEDORA-2008-0880</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/488102/100/0/threaded" xml:lang="en">20080213 rPSA-2008-0063-1 boost</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032" xml:lang="en">MDVSA-2008:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml" xml:lang="en">GLSA-200802-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2008-0063" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2008-0063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29323" xml:lang="en">29323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28943" xml:lang="en">28943</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28860" xml:lang="en">28860</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28705" xml:lang="en">28705</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28545" xml:lang="en">28545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28527" xml:lang="en">28527</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28511" xml:lang="en">28511</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html" xml:lang="en">SUSE-SR:2008:006</vuln:reference>
    </vuln:references>
    <vuln:summary>regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0172">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.06_lts"/>
          <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.10"/>
          <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:7.04"/>
          <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:7.10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:boost:boost:1.33"/>
          <cpe-lang:fact-ref name="cpe:/a:boost:boost:1.34"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:boost:boost:1.33</vuln:product>
      <vuln:product>cpe:/a:boost:boost:1.34</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0172</vuln:cve-id>
    <vuln:published-datetime>2008-01-17T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:04.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-18T09:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-2143" xml:lang="en">https://issues.rpath.com/browse/RPL-2143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0249" xml:lang="en">ADV-2008-0249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-570-1" xml:lang="en">USN-570-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27325" xml:lang="en">27325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.boost.org/trac/boost/changeset/42745" xml:lang="en">http://svn.boost.org/trac/boost/changeset/42745</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.boost.org/trac/boost/changeset/42674" xml:lang="en">http://svn.boost.org/trac/boost/changeset/42674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=205955" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=205955</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html" xml:lang="en">FEDORA-2008-0880</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/488102/100/0/threaded" xml:lang="en">20080213 rPSA-2008-0063-1 boost</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032" xml:lang="en">MDVSA-2008:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml" xml:lang="en">GLSA-200802-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2008-0063" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2008-0063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29323" xml:lang="en">29323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28943" xml:lang="en">28943</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28860" xml:lang="en">28860</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28705" xml:lang="en">28705</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28545" xml:lang="en">28545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28527" xml:lang="en">28527</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28511" xml:lang="en">28511</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html" xml:lang="en">SUSE-SR:2008:006</vuln:reference>
    </vuln:references>
    <vuln:summary>The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (NULL dereference and crash) via an invalid regular expression.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0173">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gforge:gforge:4.6.99"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gforge:gforge:4.6.99</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0173</vuln:cve-id>
    <vuln:published-datetime>2008-01-15T15:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:04.437-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-15T15:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1459" xml:lang="en">DSA-1459</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0115" xml:lang="en">ADV-2008-0115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27266" xml:lang="en">27266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39666" xml:lang="en">gforge-multiple-sql-injection(39666)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28451" xml:lang="en">28451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28395" xml:lang="en">28395</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0174">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ge_fanuc:proficy_real-time_information_portal:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ge_fanuc:proficy_real-time_information_portal:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0174</vuln:cve-id>
    <vuln:published-datetime>2008-01-28T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T21:04:42.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-29T14:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/180876" xml:lang="en">VU#180876</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/30754" xml:lang="en">30754</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487075/100/0/threaded" xml:lang="en">20080125 C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Authentication Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12459" xml:lang="en">http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12459</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019273" xml:lang="en">1019273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487244/100/0/threaded" xml:lang="en">20080129 Re: C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Authentication Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3590" xml:lang="en">3590</vuln:reference>
    </vuln:references>
    <vuln:summary>GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ge_fanuc:proficy_real-time_information_portal:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ge_fanuc:proficy_real-time_information_portal:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0175</vuln:cve-id>
    <vuln:published-datetime>2008-01-28T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:04.657-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-29T14:17:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/339345" xml:lang="en">VU#339345</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0307/references" xml:lang="en">ADV-2008-0307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019274" xml:lang="en">1019274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27446" xml:lang="en">27446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487079/100/0/threaded" xml:lang="en">20080125 C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary File Upload and Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12460" xml:lang="en">http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12460</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28678" xml:lang="en">28678</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487242/100/0/threaded" xml:lang="en">20080129 Re: C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary File Upload and Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3591" xml:lang="en">3591</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the main virtual directory.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ge_fanuc:cimplicity:6.1_sp6_hf_010708_162517_6106"/>
        <cpe-lang:fact-ref name="cpe:/a:ge_fanuc:cimplicity:7.0_sim8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ge_fanuc:cimplicity:6.1_sp6_hf_010708_162517_6106</vuln:product>
      <vuln:product>cpe:/a:ge_fanuc:cimplicity:7.0_sim8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0176</vuln:cve-id>
    <vuln:published-datetime>2008-01-28T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:04.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-29T14:23:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/308556" xml:lang="en">VU#308556</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0306" xml:lang="en">ADV-2008-0306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019275" xml:lang="en">1019275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27447" xml:lang="en">27447</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487076/100/0/threaded" xml:lang="en">20080125 C4 Security Advisory - GE Fanuc Cimplicity 6.1 Heap Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12458" xml:lang="en">http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12458</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28663" xml:lang="en">28663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487241/100/0/threaded" xml:lang="en">20080129 Re: C4 Security Advisory - GE Fanuc Cimplicity 6.1 Heap Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3592" xml:lang="en">3592</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in w32rtr.exe in GE Fanuc CIMPLICITY HMI SCADA system 7.0 before 7.0 SIM 9, and earlier versions before 6.1 SP6 Hot fix - 010708_162517_6106, allow remote attackers to execute arbitrary code via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0177">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:kame:ipcomp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kame:ipcomp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0177</vuln:cve-id>
    <vuln:published-datetime>2008-02-07T17:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:05.080-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-08T12:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/110947" xml:lang="en">VU#110947</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-150A.html" xml:lang="en">TA08-150A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27642" xml:lang="en">27642</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28788" xml:lang="en">28788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/2094/references" xml:lang="en">ADV-2008-2094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1697" xml:lang="en">ADV-2008-1697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0688" xml:lang="en">ADV-2008-0688</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0441" xml:lang="en">ADV-2008-0441</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kame.net/dev/cvsweb2.cgi/kame/kame/sys/netinet6/ipcomp_input.c.diff?r1=1.36;r2=1.37" xml:lang="en">http://www.kame.net/dev/cvsweb2.cgi/kame/kame/sys/netinet6/ipcomp_input.c.diff?r1=1.36;r2=1.37</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31074" xml:lang="en">31074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28816" xml:lang="en">28816</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html" xml:lang="en">APPLE-SA-2008-07-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/ipcomp_input.c?f=u&amp;only_with_tag=netbsd-3-1" xml:lang="en">http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/ipcomp_input.c?f=u&amp;only_with_tag=netbsd-3-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/5191" xml:lang="en">5191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019314" xml:lang="en">1019314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://security.freebsd.org/advisories/FreeBSD-SA-08:04.ipsec.asc" xml:lang="en">FreeBSD-SA-08:04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/30430" xml:lang="en">30430</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29130" xml:lang="en">29130</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28979" xml:lang="en">28979</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html" xml:lang="en">APPLE-SA-2008-05-28</vuln:reference>
    </vuln:references>
    <vuln:summary>The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0178">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:4.3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:4.3.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0178</vuln:cve-id>
    <vuln:published-datetime>2008-02-04T19:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:24.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-05T10:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/326065" xml:lang="en">VU#326065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27547" xml:lang="en">27547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.liferay.com/browse/LEP-4736" xml:lang="en">http://support.liferay.com/browse/LEP-4736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28742" xml:lang="en">28742</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the User-Agent HTTP header.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0179">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:4.3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:4.3.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0179</vuln:cve-id>
    <vuln:published-datetime>2008-02-04T19:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:24.513-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-05T10:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/888209" xml:lang="en">VU#888209</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27550" xml:lang="en">27550</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.liferay.com/browse/LEP-4737" xml:lang="en">http://support.liferay.com/browse/LEP-4737</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28742" xml:lang="en">28742</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0180">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal"/>
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:4.3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:2.1.1</vuln:product>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:4.1</vuln:product>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:4.1.1</vuln:product>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:4.3.6</vuln:product>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:4.1.3</vuln:product>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:3.6.1</vuln:product>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal</vuln:product>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:4.3.1</vuln:product>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:2.0</vuln:product>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:2.2.0</vuln:product>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:2.1.0</vuln:product>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0180</vuln:cve-id>
    <vuln:published-datetime>2008-02-04T19:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:24.670-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-05T10:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/732449" xml:lang="en">VU#732449</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27546" xml:lang="en">27546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.liferay.com/browse/LEP-4738" xml:lang="en">http://support.liferay.com/browse/LEP-4738</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28742" xml:lang="en">28742</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field in a User Profile.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0181">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:4.3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:4.3.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0181</vuln:cve-id>
    <vuln:published-datetime>2008-02-04T19:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:24.843-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-05T11:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/217825" xml:lang="en">VU#217825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27554" xml:lang="en">27554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.liferay.com/browse/LEP-4739" xml:lang="en">http://support.liferay.com/browse/LEP-4739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28742" xml:lang="en">28742</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Admin portlet in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Shutdown message.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0182">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:liferay:liferay_enterprise_portal:4.3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:liferay:liferay_enterprise_portal:4.3.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0182</vuln:cve-id>
    <vuln:published-datetime>2008-02-04T19:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:24.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-05T11:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/767825" xml:lang="en">VU#767825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.liferay.com/browse/LEP-4739" xml:lang="en">http://support.liferay.com/browse/LEP-4739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28742" xml:lang="en">28742</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0184">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:prenotazioni_on_line:syshotel_on_line_system"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:prenotazioni_on_line:syshotel_on_line_system</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0184</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T17:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:25.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T10:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27184" xml:lang="en">27184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485940/100/0/threaded" xml:lang="en">20080108 sysHotel On Line Remote File Disclosure Vulnerability.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3528" xml:lang="en">3528</vuln:reference>
    </vuln:references>
    <vuln:summary>Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded "/" ("%2F") in the file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0185">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netrisk:netrisk:1.9.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netrisk:netrisk:1.9.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0185</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T17:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-09-11T01:17:43.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T10:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27161" xml:lang="en">27161</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4852" xml:lang="en">4852</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=551208&amp;group_id=129681" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=551208&amp;group_id=129681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28328" xml:lang="en">28328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485834/100/0/threaded" xml:lang="en">20080106 netrisk 1.9.7 Multiple Remote Vulnerabilities (sql injection/xss)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the pid parameter in a profile page (possibly profile.php).</vuln:summary>
  </entry>
  <entry id="CVE-2008-0186">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phprisk:netrisk:1.9.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phprisk:netrisk:1.9.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0186</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T17:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-09-11T01:17:43.670-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T10:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27161" xml:lang="en">27161</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4852" xml:lang="en">4852</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485834/100/0/threaded" xml:lang="en">20080106 netrisk 1.9.7 Multiple Remote Vulnerabilities (sql injection/xss)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28369" xml:lang="en">28369</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in NetRisk 1.9.7 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to CVE-2008-0144.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0187">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:spacial_audio_solutions:samphpweb:4.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:spacial_audio_solutions:samphpweb:4.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0187</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T17:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:25.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T10:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39463" xml:lang="en">sambroadcaster-songinfo-sql-injection(39463)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27147" xml:lang="en">27147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4836" xml:lang="en">4836</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0188">
    <vuln:cve-id>CVE-2008-0188</vuln:cve-id>
    <vuln:published-datetime>2008-01-16T19:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T21:04:44.540-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its requester.  Further investigation showed that it was not a new security issue.  Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0189">
    <vuln:cve-id>CVE-2008-0189</vuln:cve-id>
    <vuln:published-datetime>2008-01-16T19:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T21:04:44.790-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its requester.  Further investigation showed that it was not a new security issue.  Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0190">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:awesometemplateengine:awesometemplateengine:1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:awesometemplateengine:awesometemplateengine:1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0190</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:25.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T11:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39396" xml:lang="en">awesometemplateengine-multiple-xss(39396)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27125" xml:lang="en">27125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1694/" xml:lang="en">http://websecurity.com.ua/1694/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument784.html" xml:lang="en">http://securityvulns.ru/Sdocument784.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4) data[table][1][url], or (5) data[poweredby] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0191">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0191</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:26.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T11:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39423" xml:lang="en">wordpress-p-path-disclosure(39423)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1634/" xml:lang="en">http://websecurity.com.ua/1634/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument663.html" xml:lang="en">http://securityvulns.ru/Sdocument663.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0192">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0192</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:26.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T11:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39426" xml:lang="en">wordpress-popuptitle-xss(39426)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27123" xml:lang="en">27123</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1658/" xml:lang="en">http://websecurity.com.ua/1658/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument714.html" xml:lang="en">http://securityvulns.ru/Sdocument714.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the popuptitle parameter to (1) wp-admin/post.php or (2) wp-admin/page-new.php.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0193">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1.3_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1.3_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2_revision5002"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.2_revision5003"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.2_revision5003</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.1.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.2_revision5002</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.2.0</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.3</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.2.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.1.3</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.1.3_rc1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.2.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.1.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.2.3</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.11</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.1.3_rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0193</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:26.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T11:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27123" xml:lang="en">27123</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1676/" xml:lang="en">http://websecurity.com.ua/1676/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument755.html" xml:lang="en">http://securityvulns.ru/Sdocument755.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1502" xml:lang="en">DSA-1502</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29014" xml:lang="en">29014</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0194">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0194</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:26.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T11:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1676/" xml:lang="en">http://websecurity.com.ua/1676/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument755.html" xml:lang="en">http://securityvulns.ru/Sdocument755.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1502" xml:lang="en">DSA-1502</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/29014" xml:lang="en">29014</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.  NOTE: this might be the same as CVE-2006-5705.1.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0195">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0195</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:26.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T11:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1687/" xml:lang="en">http://websecurity.com.ua/1687/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1686/" xml:lang="en">http://websecurity.com.ua/1686/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1683/" xml:lang="en">http://websecurity.com.ua/1683/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1679/" xml:lang="en">http://websecurity.com.ua/1679/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument773.html" xml:lang="en">http://securityvulns.ru/Sdocument773.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument772.html" xml:lang="en">http://securityvulns.ru/Sdocument772.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument768.html" xml:lang="en">http://securityvulns.ru/Sdocument768.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument762.html" xml:lang="en">http://securityvulns.ru/Sdocument762.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0196">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0196</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:26.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T11:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1687/" xml:lang="en">http://websecurity.com.ua/1687/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1686/" xml:lang="en">http://websecurity.com.ua/1686/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1683/" xml:lang="en">http://websecurity.com.ua/1683/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1679/" xml:lang="en">http://websecurity.com.ua/1679/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument773.html" xml:lang="en">http://securityvulns.ru/Sdocument773.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument772.html" xml:lang="en">http://securityvulns.ru/Sdocument772.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument768.html" xml:lang="en">http://securityvulns.ru/Sdocument768.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument762.html" xml:lang="en">http://securityvulns.ru/Sdocument762.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in WordPress 2.0.11 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the page parameter to certain PHP scripts under wp-admin/ or (2) the import parameter to wp-admin/admin.php, as demonstrated by discovering the full path via a request for the \..\..\wp-config pathname; and allow remote attackers to modify arbitrary files via a .. (dot dot) in the file parameter to wp-admin/templates.php.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0197">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wp-contactform:1.5_alpha"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wp-contactform:1.5_alpha</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0197</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:26.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T11:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1641/" xml:lang="en">http://websecurity.com.ua/1641/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1600/" xml:lang="en">http://websecurity.com.ua/1600/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument667.html" xml:lang="en">http://securityvulns.ru/Sdocument667.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument546.html" xml:lang="en">http://securityvulns.ru/Sdocument546.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wpcf_email, (2) wpcf_subject, (3) wpcf_question, (4) wpcf_answer, (5) wpcf_success_msg, (6) wpcf_error_msg, or (7) wpcf_msg parameter to wp-admin/admin.php, or (8) the SRC attribute of an IFRAME element.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0198">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0198</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:27.123-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T11:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1641/" xml:lang="en">http://websecurity.com.ua/1641/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1600/" xml:lang="en">http://websecurity.com.ua/1600/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument667.html" xml:lang="en">http://securityvulns.ru/Sdocument667.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument546.html" xml:lang="en">http://securityvulns.ru/Sdocument546.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site request forgery (CSRF) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) wpcf_question, (2) wpcf_success_msg, or (3) wpcf_error_msg parameter to wp-admin/admin.php.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0199">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pro_search:pro_search:0.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pro_search:pro_search:0.16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0199</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:27.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T11:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1259/" xml:lang="en">http://websecurity.com.ua/1259/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument731.html" xml:lang="en">http://securityvulns.ru/Sdocument731.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>PRO-Search 0.17 and earlier allows remote attackers to cause a denial of service via certain values of the show_page and time parameters to the default URI.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0200">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:medialand:rotabanner_local:3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:medialand:rotabanner_local:3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0200</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-09-11T01:17:44.813-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T12:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27138" xml:lang="en">27138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1442/" xml:lang="en">http://websecurity.com.ua/1442/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument625.html" xml:lang="en">http://securityvulns.ru/Sdocument625.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in account/index.html in RotaBanner Local 3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) drop parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0201">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:expressionengine:expressionengine:1.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:expressionengine:expressionengine:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0201</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-10-22T01:44:13.437-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T12:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39442" xml:lang="en">expressionengine-index-xss(39442)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27128" xml:lang="en">27128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1454/" xml:lang="en">http://websecurity.com.ua/1454/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument472.html" xml:lang="en">http://securityvulns.ru/Sdocument472.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0202">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:expressionengine:expressionengine:1.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:expressionengine:expressionengine:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0202</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-10-22T01:44:13.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T13:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27128" xml:lang="en">27128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1454/" xml:lang="en">http://websecurity.com.ua/1454/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument472.html" xml:lang="en">http://securityvulns.ru/Sdocument472.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0203">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:cryptographp:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:cryptographp:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0203</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:27.857-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T13:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1596/" xml:lang="en">http://websecurity.com.ua/1596/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in cryptographp/admin.php in the Cryptographp 1.2 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cryptwidth, (2) cryptheight, (3) bgimg, (4) charR, (5) charG, (6) charB, (7) charclear, (8) tfont, (9) charel, (10) charelc, (11) charelv, (12) charnbmin, (13) charnbmax, (14) charspace, (15) charsizemin, (16) charsizemax, (17) charanglemax, (18) noisepxmin, (19) noisepxmax, (20) noiselinemin, (21) noiselinemax, (22) nbcirclemin, (23) nbcirclemax, or (24) brushsize parameter to wp-admin/options-general.php.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0204">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:math_comment_spam_protection_plugin:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:math_comment_spam_protection_plugin:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0204</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:27.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T13:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1576/" xml:lang="en">http://websecurity.com.ua/1576/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0205">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:math_comment_spam_protection_plugin:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:math_comment_spam_protection_plugin:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0205</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:28.153-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T13:09:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1576/" xml:lang="en">http://websecurity.com.ua/1576/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0206">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:captcha:2.5d"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:captcha:2.5d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0206</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:28.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T13:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1588/" xml:lang="en">http://websecurity.com.ua/1588/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in captcha\captcha.php in the Captcha! 2.5d and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) captcha_ttffolder, (2) captcha_numchars, (3) captcha_ttfrange, or (4) captcha_secret parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0207">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pro_search:pro_search:0.17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pro_search:pro_search:0.17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0207</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:28.450-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T13:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27126" xml:lang="en">27126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websecurity.com.ua/1259/" xml:lang="en">http://websecurity.com.ua/1259/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.ru/Sdocument731.html" xml:lang="en">http://securityvulns.ru/Sdocument731.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28335" xml:lang="en">28335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" xml:lang="en">20080103 securityvulns.com russian vulnerabilities digest</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3539" xml:lang="en">3539</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prot, (2) host, (3) path, (4) name, (5) ext, (6) size, (7) search_days, or (8) show_page parameter to the default URI.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0208">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.05"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.04"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.03"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.02"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.03"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.01"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.02"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.2.03"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.1:sr4"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.1:sr4</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.02</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.03</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.05</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.1</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.01</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.0</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.04</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.02</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.2.03</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0208</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-24T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T13:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27162" xml:lang="en">27162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded" xml:lang="en">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt" xml:lang="en">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28284" xml:lang="en">28284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://hackerscenter.com/archive/view.asp?id=28145" xml:lang="en">http://hackerscenter.com/archive/view.asp?id=28145</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in login.asp in Snitz Forums 2000 3.4.05 and earlier allows remote attackers to inject arbitrary web script or HTML via the target parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0209">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.04"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.03"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.02"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.03"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.01"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.3.02"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.2.03"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.1:sr4"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.05"/>
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.4.06"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.1:sr4</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.02</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.05</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.03</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.1</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.01</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.0</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.04</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.02</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.4.06</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.2.03</vuln:product>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.3.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0209</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-24T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T13:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded" xml:lang="en">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt" xml:lang="en">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://hackerscenter.com/archive/view.asp?id=28145" xml:lang="en">http://hackerscenter.com/archive/view.asp?id=28145</vuln:reference>
    </vuln:references>
    <vuln:summary>Open redirect vulnerability in Forums/login.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to redirect users to arbitrary web sites via a URL in the target parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0210">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:uebimiau:webmail:2.7.10"/>
        <cpe-lang:fact-ref name="cpe:/a:uebimiau:webmail:2.7.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:uebimiau:webmail:2.7.2</vuln:product>
      <vuln:product>cpe:/a:uebimiau:webmail:2.7.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0210</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:28.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-10T13:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27154" xml:lang="en">27154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4846" xml:lang="en">4846</vuln:reference>
    </vuln:references>
    <vuln:summary>Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting.  NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0211">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:compaq:2210_series_bios:f.04"/>
        <cpe-lang:fact-ref name="cpe:/h:compaq:2510_series_bios:f.08"/>
        <cpe-lang:fact-ref name="cpe:/h:compaq:2710_series_bios:f.0d"/>
        <cpe-lang:fact-ref name="cpe:/h:compaq:6510_series_bios:f.0f"/>
        <cpe-lang:fact-ref name="cpe:/h:compaq:6515_series_bios:f.0a"/>
        <cpe-lang:fact-ref name="cpe:/h:compaq:6520_series_bios:f.08"/>
        <cpe-lang:fact-ref name="cpe:/h:compaq:6710_series_bios:f.0f"/>
        <cpe-lang:fact-ref name="cpe:/h:compaq:6715_series_bios:f.0a"/>
        <cpe-lang:fact-ref name="cpe:/h:compaq:6720_series_bios:f.08"/>
        <cpe-lang:fact-ref name="cpe:/h:compaq:6820_series_bios:f.08"/>
        <cpe-lang:fact-ref name="cpe:/h:compaq:6910_series_bios:f.11"/>
        <cpe-lang:fact-ref name="cpe:/h:compaq:8510_series_bios:f.0e"/>
        <cpe-lang:fact-ref name="cpe:/h:compaq:8710_series_bios:f.08"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:compaq:6515_series_bios:f.0a</vuln:product>
      <vuln:product>cpe:/h:compaq:2510_series_bios:f.08</vuln:product>
      <vuln:product>cpe:/h:compaq:2210_series_bios:f.04</vuln:product>
      <vuln:product>cpe:/h:compaq:6520_series_bios:f.08</vuln:product>
      <vuln:product>cpe:/h:compaq:6715_series_bios:f.0a</vuln:product>
      <vuln:product>cpe:/h:compaq:6710_series_bios:f.0f</vuln:product>
      <vuln:product>cpe:/h:compaq:6720_series_bios:f.08</vuln:product>
      <vuln:product>cpe:/h:compaq:2710_series_bios:f.0d</vuln:product>
      <vuln:product>cpe:/h:compaq:6910_series_bios:f.11</vuln:product>
      <vuln:product>cpe:/h:compaq:6510_series_bios:f.0f</vuln:product>
      <vuln:product>cpe:/h:compaq:8710_series_bios:f.08</vuln:product>
      <vuln:product>cpe:/h:compaq:6820_series_bios:f.08</vuln:product>
      <vuln:product>cpe:/h:compaq:8510_series_bios:f.0e</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0211</vuln:cve-id>
    <vuln:published-datetime>2008-03-31T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:08.500-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-04-01T10:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120672155821700&amp;w=2" xml:lang="en">HPSBGN02305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/41520" xml:lang="en">compaq-businessnotebook-pcbios-dos(41520)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1042/references" xml:lang="en">ADV-2008-1042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28494" xml:lang="en">28494</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019729" xml:lang="en">1019729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120672155821700&amp;w=2" xml:lang="en">SSRT080004</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the BIOS F.04 through F.11 for the HP Compaq Business Notebook PC allows local users to cause a denial of service via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0212">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.23"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
          <cpe-lang:fact-ref name="cpe:/o:sun:solaris"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.41"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.01"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.51"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.01</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.51</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.41</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0212</vuln:cve-id>
    <vuln:published-datetime>2008-02-06T16:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-25T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-07T08:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27629" xml:lang="en">27629</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0424" xml:lang="en">ADV-2008-0424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019306" xml:lang="en">1019306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487586/100/0/threaded" xml:lang="en">SSRT071420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/487586/100/0/threaded" xml:lang="en">SSRT071420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28798" xml:lang="en">28798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=652" xml:lang="en">20080204 Hewlett-Packard Network Node Manager Topology Manager Service DoS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>ovtopmd in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to cause a denial of service (crash) via a crafted TCP request that triggers an out-of-bounds memory access.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0213">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:virtual_rooms:6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:virtual_rooms:6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0213</vuln:cve-id>
    <vuln:published-datetime>2008-02-07T17:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-05-18T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-08T12:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019311" xml:lang="en">1019311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120231595903371&amp;w=2" xml:lang="en">HPSBGN02310</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120231595903371&amp;w=2" xml:lang="en">HPSBGN02310</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in a certain ActiveX control for HP Virtual Rooms (HPVR) 6 and earlier allows remote attackers to execute arbitrary code via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0214">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:select_identity:4.00"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:select_identity:4.01"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:select_identity:4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:select_identity:4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:select_identity:4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:select_identity:4.13"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:select_identity:4.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:select_identity:4.10</vuln:product>
      <vuln:product>cpe:/a:hp:select_identity:4.01</vuln:product>
      <vuln:product>cpe:/a:hp:select_identity:4.12</vuln:product>
      <vuln:product>cpe:/a:hp:select_identity:4.11</vuln:product>
      <vuln:product>cpe:/a:hp:select_identity:4.20</vuln:product>
      <vuln:product>cpe:/a:hp:select_identity:4.00</vuln:product>
      <vuln:product>cpe:/a:hp:select_identity:4.13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0214</vuln:cve-id>
    <vuln:published-datetime>2008-02-07T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:09.063-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-08T13:23:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120239931201443&amp;w=2" xml:lang="en">SSRT080013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0472" xml:lang="en">ADV-2008-0472</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27667" xml:lang="en">27667</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120239931201443&amp;w=2" xml:lang="en">HPSBMA02309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019322" xml:lang="en">1019322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28844" xml:lang="en">28844</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to gain access via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0215">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:storage_essentials_srm_enterprise:5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:storage_essentials_srm_standard:5.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:storage_essentials_srm_enterprise:5.1.3</vuln:product>
      <vuln:product>cpe:/a:hp:storage_essentials_srm_standard:5.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0215</vuln:cve-id>
    <vuln:published-datetime>2008-02-11T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:09.173-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-02-12T13:07:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0440" xml:lang="en">ADV-2008-0440</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019312" xml:lang="en">1019312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27643" xml:lang="en">27643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28813" xml:lang="en">28813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01316132" xml:lang="en">SSRT071474</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01316132" xml:lang="en">SSRT071474</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in HP Storage Essentials Storage Resource Management (SRM) before 6.0.0 allow remote attackers to obtain unspecified access to a managed device via unknown attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0216">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.0:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.0:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.1:release"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.1:release_p10"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.1:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:7.0:current"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:7.0:pre-release"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.0:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.1:stable</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.1:release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:7.0:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.1:release_p10</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:7.0:current</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:7.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.0:release</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0216</vuln:cve-id>
    <vuln:published-datetime>2008-01-15T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:29.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-16T12:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc" xml:lang="en">FreeBSD-SA-08:01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39667" xml:lang="en">freebsd-ptsname-information-disclosure(39667)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019191" xml:lang="en">1019191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27284" xml:lang="en">27284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28498" xml:lang="en">28498</vuln:reference>
    </vuln:references>
    <vuln:summary>The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0217">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:7.0:pre-release"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:5.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:7.0:pre-release</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0217</vuln:cve-id>
    <vuln:published-datetime>2008-01-15T21:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:30.043-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-16T13:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc" xml:lang="en">FreeBSD-SA-08:01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39665" xml:lang="en">freebsd-openpty-information-disclosure(39665)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019191" xml:lang="en">1019191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27284" xml:lang="en">27284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28498" xml:lang="en">28498</vuln:reference>
    </vuln:references>
    <vuln:summary>The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0218">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:merak:icewarp_mail_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:merak:icewarp_mail_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0218</vuln:cve-id>
    <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:09.423-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-11T09:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39564" xml:lang="en">icewarpmailserver-index-xss(39564)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0135" xml:lang="en">ADV-2008-0135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/data/vulnerabilities/exploits/27189.html" xml:lang="en">http://www.securityfocus.com/data/vulnerabilities/exploits/27189.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27189" xml:lang="en">27189</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28460" xml:lang="en">28460</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HTML via the message parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0219">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php_webquest:php_webquest:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php_webquest:php_webquest:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0219</vuln:cve-id>
    <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-10-11T01:48:43.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-11T09:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39560" xml:lang="en">webquest-soportehorizontalw-sql-injection(39560)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27192" xml:lang="en">27192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4867" xml:lang="en">4867</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/26821" xml:lang="en">26821</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different vector than CVE-2007-4920.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0220">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gateway:cweblaunchctl_activex_control:1.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gateway:weblaunch"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gateway:weblaunch</vuln:product>
      <vuln:product>cpe:/a:gateway:cweblaunchctl_activex_control:1.0.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0220</vuln:cve-id>
    <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:09.597-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-11T10:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/735441" xml:lang="en">VU#735441</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0077" xml:lang="en">ADV-2008-0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27193" xml:lang="en">27193</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4982" xml:lang="en">4982</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4869" xml:lang="en">4869</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28379" xml:lang="en">28379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=119984138526735&amp;w=2" xml:lang="en">20080109 Gateway WebLaunch ActiveX Control Insecure Method</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth argument to the DoWebLaunch method.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0221">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gateway:weblaunch:1.0.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gateway:weblaunch:1.0.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0221</vuln:cve-id>
    <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:09.687-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-11T10:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0077" xml:lang="en">ADV-2008-0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4869" xml:lang="en">4869</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28379" xml:lang="en">28379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=119984138526735&amp;w=2" xml:lang="en">20080109 Gateway WebLaunch ActiveX Control Insecure Method</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote attackers to execute arbitrary programs via a ..\ (dot dot backslash) in the second argument to the DoWebLaunch method.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0222">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:filemanager:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:filemanager:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0222</vuln:cve-id>
    <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:30.810-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-11T10:05:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39462" xml:lang="en">wordpress-wpfilemanager-file-upload(39462)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27151" xml:lang="en">27151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/4844" xml:lang="en">4844</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0223">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:12.0"/>
        <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:13.0"/>
        <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:2006"/>
        <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro:linux"/>
        <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro_lite2"/>
        <cpe-lang:fact-ref name="cpe:/a:justsystem:ichitaro_viewer"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:justsystem:ichitaro_lite2</vuln:product>
      <vuln:product>cpe:/a:justsystem:ichitaro:12.0</vuln:product>
      <vuln:product>cpe:/a:justsystem:ichitaro:2007</vuln:product>
      <vuln:product>cpe:/a:justsystem:ichitaro:linux</vuln:product>
      <vuln:product>cpe:/a:justsystem:ichitaro_viewer</vuln:product>
      <vuln:product>cpe:/a:justsystem:ichitaro:2004</vuln:product>
      <vuln:product>cpe:/a:justsystem:ichitaro:2006</vuln:product>
      <vuln:product>cpe:/a:justsystem:ichitaro:11.0</vuln:product>
      <vuln:product>cpe:/a:justsystem:ichitaro:2005</vuln:product>
      <vuln:product>cpe:/a:justsystem:ichitaro:13.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0223</vuln:cve-id>
    <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:04:10.157-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-11T10:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39501" xml:lang="en">justsystems-jsfc-bo(39501)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0045" xml:lang="en">ADV-2008-0045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019168" xml:lang="en">1019168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27153" xml:lang="en">27153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.justsystems.com/jp/info/pd8001.html" xml:lang="en">http://www.justsystems.com/jp/info/pd8001.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20080107" xml:lang="en">http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20080107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28275" xml:lang="en">28275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/jp/JVN%2308237857/index.html" xml:lang="en">JVN#08237857</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in JustSystems JSFC.DLL, as used in multiple JustSystems products such as Ichitaro, allows remote attackers to execute arbitrary code via a crafted .JTD file.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0224">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:runcms:runcms:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:runcms:runcms:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:runcms:runcms:1.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:runcms:runcms:1.6</vuln:product>
      <vuln:product>cpe:/a:runcms:runcms:1.6.1</vuln:product>
      <vuln:product>cpe:/a:runcms:runcms:1.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0224</vuln:cve-id>
    <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:34:31.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-11T10:09:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/39478" xml:lang="en">runcms-newbb-client-sql-injection(39478)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27152" xml:lang="en">27152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28340" xml:lang="en">28340</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/4845" xml:lang="en">4845</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL commands via the Client-Ip parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0225">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xine:xine-lib:1.1.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xine:xine-lib:1.1.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2008-0225</vuln:cve-id>
    <vuln:published-datetime>2008-01-10T18:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-17T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2008-01-11T10:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00592.html" xml:lang="en">FEDORA-2008-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=428620" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=428620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0163" xml:lang="en">ADV-2008-0163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-635-1" xml:lang="en">USN-635-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27198" xml:lang="en">27198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/suse_security_summary_report.html" xml:lang="en">SUSE-SR:2008:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:045" xml:lang="en">MDVSA-2008:045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:020" xml:lang="en">MDVSA-2008:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1472" xml:lang="en">DSA-1472</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=567872" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=567872</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200801-12.xml" xml:lang="en">GLSA-200801-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/31393" xml:lang="en">31393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28955" xml:lang="en">28955</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28674" xml:lang="en">28674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28636" xml:lang="en">28636</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28507" xml:lang="en">28507</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28489" xml:lang="en">28489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/28384" xml:lang="en">28384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=205197" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=205197</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/xinermffhof-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/xinermffhof-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function and related to disregarding the max field.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2008-0226">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe