<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" nvd_xml_version="2.0" pub_date="2009-11-23T03:15:00" xsi:schemaLocation="http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
    <entry id="CVE-2009-0022">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:samba:samba:3.2.6</vuln:product>
            <vuln:product>cpe:/a:samba:samba:3.2.5</vuln:product>
            <vuln:product>cpe:/a:samba:samba:3.2.1</vuln:product>
            <vuln:product>cpe:/a:samba:samba:3.2.2</vuln:product>
            <vuln:product>cpe:/a:samba:samba:3.2.3</vuln:product>
            <vuln:product>cpe:/a:samba:samba:3.2.4</vuln:product>
            <vuln:product>cpe:/a:samba:samba:3.2.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0022</vuln:cve-id>
        <vuln:published-datetime>2009-01-05T15:30:02.390-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-03-13T01:46:01.563-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-06T10:37:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00309.html">FEDORA-2009-0268</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47733">samba-file-system-security-bypass(47733)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-702-1">USN-702-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021513">1021513</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33118">33118</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.samba.org/samba/security/CVE-2009-0022.html">http://www.samba.org/samba/security/CVE-2009-0022.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:042">MDVSA-2009:042</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0017">ADV-2009-0017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33431">33431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33392">33392</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33379">33379</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/51152">51152</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://master.samba.org/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch">http://master.samba.org/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch</vuln:reference>
        </vuln:references>
        <vuln:summary>Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection request that specifies a blank share name.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0021">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ntp:ntp:4.2.4p4" />
                <cpe-lang:fact-ref name="cpe:/a:ntp:ntp:4.2.4p3" />
                <cpe-lang:fact-ref name="cpe:/a:ntp:ntp:4.2.4p2" />
                <cpe-lang:fact-ref name="cpe:/a:ntp:ntp:4.2.4p1" />
                <cpe-lang:fact-ref name="cpe:/a:ntp:ntp:4.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:ntp:ntp:4.2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ntp:ntp:4.2.0</vuln:product>
            <vuln:product>cpe:/a:ntp:ntp:4.2.4p1</vuln:product>
            <vuln:product>cpe:/a:ntp:ntp:4.2.2</vuln:product>
            <vuln:product>cpe:/a:ntp:ntp:4.2.4p2</vuln:product>
            <vuln:product>cpe:/a:ntp:ntp:4.2.4p3</vuln:product>
            <vuln:product>cpe:/a:ntp:ntp:4.2.4p4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0021</vuln:cve-id>
        <vuln:published-datetime>2009-01-07T12:30:00.360-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-08-26T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-07T14:42:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0042">ADV-2009-0042</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="https://lists.ntp.org/pipermail/announce/2009-January/000055.html">[announce] 20090108 NTP 4.2.4p6 Released</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021533">1021533</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-0046.html">RHSA-2009:0046</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ocert.org/advisories/ocert-2008-016.html">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.531177">SSA:2009-014-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35074">35074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34642">34642</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33648">33648</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33558">33558</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33406">33406</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html">SUSE-SR:2009:008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html">SUSE-SR:2009:005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</vuln:reference>
        </vuln:references>
        <vuln:summary>NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0025">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:isc:bind" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.10" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.5:p1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.5" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4.7" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.5-p2-w1:windows" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2:p1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.8" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.9" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.6" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.7" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.5" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.7" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.0" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.3_t9b" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.3_t1a" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p6" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p5" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p7" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.2:p3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4.5" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.6" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4.4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.7" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.9" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0b1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a5" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a6" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0b2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0b3" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0b4" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:isc:bind:9.2.1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.2.2</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.2.3</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.2.4</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.2.5</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.2.6</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.3.5-p2-w1:windows</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.2.7</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.2.9</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.3.0</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.3.1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.3.2</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.3.3</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.0</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.2</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.3</vuln:product>
            <vuln:product>cpe:/a:isc:bind:4.9.9</vuln:product>
            <vuln:product>cpe:/a:isc:bind:4.9.8</vuln:product>
            <vuln:product>cpe:/a:isc:bind:4.9.7</vuln:product>
            <vuln:product>cpe:/a:isc:bind:4.9.6</vuln:product>
            <vuln:product>cpe:/a:isc:bind:4.9.5</vuln:product>
            <vuln:product>cpe:/a:isc:bind:4.9.4</vuln:product>
            <vuln:product>cpe:/a:isc:bind:4.9.3</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.3_t9b</vuln:product>
            <vuln:product>cpe:/a:isc:bind:4.9.2</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.2.2:p3</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.2.0</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2:p1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.0b4</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.0b3</vuln:product>
            <vuln:product>cpe:/a:isc:bind:4.9.10</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.0b2</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.0b1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.3.0</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.1.1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.1.2</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.4.1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.0.1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.4.7</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.4.4</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.4.5</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.1.1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.2:p1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:4.9</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.2:p2</vuln:product>
            <vuln:product>cpe:/a:isc:bind:4.9.5:p1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.2:p3</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.2:p4</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.2:p5</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.2:p6</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.2:p7</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.0a5</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.0a4</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.0a6</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.0a1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.1.2</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.1.3</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.0a3</vuln:product>
            <vuln:product>cpe:/a:isc:bind:4</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.0a2</vuln:product>
            <vuln:product>cpe:/a:isc:bind</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.4</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.3_t1a</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.3.5</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.3.6</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.3.1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.3.2</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.3.3</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.3.4</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.2</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4.0:rc1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.3</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.4</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.0</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.5</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.1</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.6</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.2</vuln:product>
            <vuln:product>cpe:/a:isc:bind:8.2.7</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.3</vuln:product>
            <vuln:product>cpe:/a:isc:bind:9.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0025</vuln:cve-id>
        <vuln:published-datetime>2009-01-07T12:30:00.390-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-05-16T01:28:42.717-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-07T14:58:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00393.html">FEDORA-2009-0350</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.isc.org/node/373">https://www.isc.org/node/373</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-2938">https://issues.rpath.com/browse/RPL-2938</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/0904">ADV-2009-0904</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/security/advisories/VMSA-2009-0004.html">http://www.vmware.com/security/advisories/VMSA-2009-0004.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/502322/100/0/threaded">20090401 VMSA-2009-0004 ESX Service Console updates for openssl, bind, and vim</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/500207/100/0/threaded">20090120 rPSA-2009-0009-1 bind bind-utils</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openbsd.org/errata44.html#008_bind">http://www.openbsd.org/errata44.html#008_bind</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ocert.org/advisories/ocert-2008-016.html">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0366">ADV-2009-0366</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0043">ADV-2009-0043</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/Advisories:rPSA-2009-0009">http://wiki.rpath.com/Advisories:rPSA-2009-0009</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2009-045.htm">http://support.avaya.com/elmodocs2/security/ASA-2009-045.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-250846-1">250846</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.540362">SSA:2009-014-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.freebsd.org/advisories/FreeBSD-SA-09:04.bind.asc">FreeBSD-SA-09:04</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35074">35074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33882">33882</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33683">33683</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33559">33559</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33551">33551</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33546">33546</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33494">33494</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33">http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33</vuln:reference>
        </vuln:references>
        <vuln:summary>BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0046">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sun:grid_engine:5.3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:grid_engine:5.3:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:sun:grid_engine:5.3:beta1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sun:grid_engine:5.3:beta1</vuln:product>
            <vuln:product>cpe:/a:sun:grid_engine:5.3:beta2</vuln:product>
            <vuln:product>cpe:/a:sun:grid_engine:5.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0046</vuln:cve-id>
        <vuln:published-datetime>2009-01-07T13:30:01.453-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-28T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-07T15:07:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ocert.org/advisories/ocert-2008-016.html">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0045">ADV-2009-0045</vuln:reference>
        </vuln:references>
        <vuln:summary>Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0047">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.99" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.91" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.91a" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.91b" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.90a" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.90b" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.90c" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.21" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.20a" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.19" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.19a" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.19b" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.18" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.18b" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.18c" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.17" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.17a" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.16" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.16a" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.15" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.15b" />
                <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.15c" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:gale:gale:0.99</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.20a</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.19b</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.19a</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.18b</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.91b</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.90c</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.17a</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.90a</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.18c</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.90b</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.21</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.16a</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.91a</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.91</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.18</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.17</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.15c</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.15b</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.19</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.16</vuln:product>
            <vuln:product>cpe:/a:gale:gale:0.15</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0047</vuln:cve-id>
        <vuln:published-datetime>2009-01-07T13:30:13.280-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-27T01:41:48.280-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-07T16:45:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ocert.org/advisories/ocert-2008-016.html">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0046">ADV-2009-0046</vuln:reference>
        </vuln:references>
        <vuln:summary>Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0048">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:openevidence:openevidence:1.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:openevidence:openevidence:1.0.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openevidence:openevidence:1.0.6</vuln:product>
            <vuln:product>cpe:/a:openevidence:openevidence:1.0.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0048</vuln:cve-id>
        <vuln:published-datetime>2009-01-07T13:30:15.827-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-27T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-07T16:57:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ocert.org/advisories/ocert-2008-016.html">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0047">ADV-2009-0047</vuln:reference>
        </vuln:references>
        <vuln:summary>OpenEvidence 1.0.6 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0049">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:eid:eidlib:2.6.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:eid:eidlib:2.6.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0049</vuln:cve-id>
        <vuln:published-datetime>2009-01-07T13:30:15.843-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-03-13T01:46:06.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-07T17:01:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ocert.org/advisories/ocert-2008-016.html">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34029">34029</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html">SUSE-SR:2009:005</vuln:reference>
        </vuln:references>
        <vuln:summary>Belgian eID middleware (eidlib) 2.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0050">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:lasso:lasso:2.2.1-0" />
                <cpe-lang:fact-ref name="cpe:/a:lasso:lasso:2.0.0-1" />
                <cpe-lang:fact-ref name="cpe:/a:lasso:lasso:1.9.9.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:lasso:lasso:2.2.1-0</vuln:product>
            <vuln:product>cpe:/a:lasso:lasso:2.0.0-1</vuln:product>
            <vuln:product>cpe:/a:lasso:lasso:1.9.9.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0050</vuln:cve-id>
        <vuln:published-datetime>2009-01-07T13:30:15.860-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-12T01:56:25.670-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-07T17:07:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47837">openssl-dsa-verify-security-bypass(47837)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ocert.org/advisories/ocert-2008-016.html">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
        </vuln:references>
        <vuln:summary>Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0051">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.28" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.27" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.26" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.25" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.22" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.21" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.20" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.19" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.18" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.17" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.16" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.15" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.14" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.13" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.12" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.11" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.10" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.9" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.8" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.7" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.6" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.5" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.4" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.3" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.2" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.1" />
                <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.29" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:zxid:zxid:0.22</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.21</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.20</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.27</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.26</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.25</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.28</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.29</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.6</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.7</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.8</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.9</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.2</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.3</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.4</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.5</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.14</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.13</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.16</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.15</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.10</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.1</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.12</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.11</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.17</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.18</vuln:product>
            <vuln:product>cpe:/a:zxid:zxid:0.19</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0051</vuln:cve-id>
        <vuln:published-datetime>2009-01-07T13:30:15.890-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-12T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-07T17:28:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47837">openssl-dsa-verify-security-bypass(47837)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ocert.org/advisories/ocert-2008-016.html">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
        </vuln:references>
        <vuln:summary>ZXID 0.29 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0065">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23_rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24_rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24_rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22_rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22_rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24_rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.2.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.12::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.11::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.8::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.7::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.6::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.4::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.3::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.10::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.1::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.9::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.8::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22_rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22_rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.10::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.7::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.9::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23_rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.6::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.11::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24_rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24_rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.4::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.3::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24_rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.12::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.2::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.1::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.2.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.5::x86_64</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0065</vuln:cve-id>
        <vuln:published-datetime>2009-01-07T14:30:00.280-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-08-12T01:25:38.170-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-08T07:55:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01045.html">FEDORA-2009-0816</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=478800">https://bugzilla.redhat.com/show_bug.cgi?id=478800</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/2193">ADV-2009-2193</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-751-1">USN-751-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1022698">1022698</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33113">33113</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-1055.html">RHSA-2009:1055</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-0331.html">RHSA-2009:0331</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-0053.html">RHSA-2009:0053</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2009/01/05/1">[oss-security] 20090105 CVE request: kernel: sctp: memory overflow when FWD-TSN chunk is received with bad stream ID</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0029">ADV-2009-0029</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2009/dsa-1794">DSA-1794</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2009/dsa-1787">DSA-1787</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2009/dsa-1749">DSA-1749</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm">http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/36191">36191</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35394">35394</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35390">35390</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35174">35174</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35011">35011</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34981">34981</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34762">34762</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34680">34680</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34394">34394</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34252">34252</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33858">33858</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33854">33854</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33674">33674</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2009-0264.html">RHSA-2009:0264</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://patchwork.ozlabs.org/patch/15024/">http://patchwork.ozlabs.org/patch/15024/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html">SUSE-SA:2009:031</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html">SUSE-SA:2009:030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html">SUSE-SA:2009:010</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01832118">HPSBNS02449</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01832118">HPSBNS02449</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9fcb95a105758b81ef0131cd18e2db5149f13e95">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9fcb95a105758b81ef0131cd18e2db5149f13e95</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 allows remote attackers to have an unknown impact via an FWD-TSN (aka FORWARD-TSN) chunk with a large stream ID.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0066">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:intel:trusted_execution_technology:_nil_" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:intel:trusted_execution_technology:_nil_</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0066</vuln:cve-id>
        <vuln:published-datetime>2009-01-07T14:30:00.297-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-08T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.6</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-08T08:52:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33119">33119</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://theinvisiblethings.blogspot.com/2009/01/attacking-intel-trusted-execution.html">http://theinvisiblethings.blogspot.com/2009/01/attacking-intel-trusted-execution.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://invisiblethingslab.com/press/itl-press-2009-01.pdf">http://invisiblethingslab.com/press/itl-press-2009-01.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Wojtczuk">http://blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Wojtczuk</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple unspecified vulnerabilities in Intel system software for Trusted Execution Technology (TXT) allow attackers to bypass intended loader integrity protections, as demonstrated by exploitation of tboot.  NOTE: as of 20090107, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0068">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:freedesktop:xdg-utils:1.0" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:freedesktop:xdg-utils:1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0068</vuln:cve-id>
        <vuln:published-datetime>2009-01-07T14:30:00.313-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-10T01:59:42.920-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-08T08:38:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-94" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugs.freedesktop.org/show_bug.cgi?id=19377">https://bugs.freedesktop.org/show_bug.cgi?id=19377</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33137">33137</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2009/01/06/1">[oss-security] 20090106 Fwd: Using xdg-open in /etc/mailcap causes hole in Firefox (Demonstration/Exploit included)</vuln:reference>
        </vuln:references>
        <vuln:summary>Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0069">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_02::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_07::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_01::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_08::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_04::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_05::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_03::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_06::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_09::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_10::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_101::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_15::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_13::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_100::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_14::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_11::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_12::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_104::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_21::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_20::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_19::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_25::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_17::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_24::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_23::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_18::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_16::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_22::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_28::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_33::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_27::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_34::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_26::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_35::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_32::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_31::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_30::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_29::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_40::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_41::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_42::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_36::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_43::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_37::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_44::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_38::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_45::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_39::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_48::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_55::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_47::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_54::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_50::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_49::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_52::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_51::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_53::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_46::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_57::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_56::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_59::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_65::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_58::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_64::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_61::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_63::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_60::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_62::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_71::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_68::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_72::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_67::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_70::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_66::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_74::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_73::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_69::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_75::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_78::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_84::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_77::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_83::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_79::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_85::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_80::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_76::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_82::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_81::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_86::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_87::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_88::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_89::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_90::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_91::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_92::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_93::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_94::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_95::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_99::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_98::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_97::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_96::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_03::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_08::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_02::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_09::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_05::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_06::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_04::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_07::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_01::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_10::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_101::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_100::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_11::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_12::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_13::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_14::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_15::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_21::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_20::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_19::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_25::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_24::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_18::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_23::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_16::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_17::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_22::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_28::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_27::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_33::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_26::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_34::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_35::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_32::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_31::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_30::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_29::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_40::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_41::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_42::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_43::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_36::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_44::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_37::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_45::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_38::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_39::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_48::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_47::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_55::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_50::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_49::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_52::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_51::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_54::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_46::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_53::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_57::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_56::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_59::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_65::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_58::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_64::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_61::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_63::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_60::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_62::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_68::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_71::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_67::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_72::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_66::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_70::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_74::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_73::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_75::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_69::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_78::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_85::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_77::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_84::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_79::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_81::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_80::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_76::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_83::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_82::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_87::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_88::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_86::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_92::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_91::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_90::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_89::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_95::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_94::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_93::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_99::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_97::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_98::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_96::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:opensolaris:snv_65::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_15::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_41::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_91::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_48::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_101::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_22::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_30::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_58::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_53::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_36::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_22::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_81::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:10::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_28::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_97::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_47::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_09::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_34::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_81::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_77::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_96::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_65::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_34::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_96::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_91::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_95::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_08::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_32::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_72::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_104::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_100::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_90::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_04::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_60::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_83::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_64::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_42::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_97::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_10::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_32::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_28::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_77::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_89::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_75::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_89::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:10::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_16::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_30::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_87::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_71::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_58::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_85::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_79::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_90::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_20::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_67::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_43::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_40::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_56::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_07::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_41::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_29::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_08::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_17::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_75::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_57::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_52::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_19::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_66::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_95::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_51::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_15::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_80::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_76::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_04::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_38::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_61::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_54::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_36::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_52::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_59::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_06::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_42::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_84::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_21::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_26::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_02::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_63::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_12::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_49::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_23::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_47::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_88::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_39::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_72::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_11::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_24::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_27::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_73::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_69::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_50::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_92::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_25::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_20::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_94::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_29::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_33::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_68::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_93::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_05::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_14::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_37::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_06::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_35::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_48::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_13::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_18::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_93::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_37::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_62::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_21::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_80::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_46::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_82::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_44::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_50::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_31::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_19::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_99::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_61::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_13::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_25::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_98::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_74::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_86::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_82::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_84::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_74::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_78::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_63::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_101::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_62::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_55::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_70::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_45::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_94::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_01::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_55::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_86::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_73::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_88::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_01::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_98::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_35::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_54::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_69::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_76::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_83::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_51::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_66::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_67::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_40::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_68::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_64::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_23::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_09::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_07::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_71::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_78::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_79::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_14::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_16::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_53::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_70::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_24::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_27::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_31::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_99::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_26::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_39::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_12::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_92::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_11::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_85::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_49::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_10::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_46::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_03::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_57::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_59::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_87::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_43::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_05::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_100::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_33::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_03::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_45::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_17::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_44::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_60::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_56::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_02::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_38::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_18::sparc</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0069</vuln:cve-id>
        <vuln:published-datetime>2009-01-07T15:30:00.467-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-24T23:47:02.967-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.9</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-08T09:26:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139466-02-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139466-02-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47750">solaris-nfs4client-dos(47750)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021519">1021519</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33128">33128</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0030">ADV-2009-0030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-248566-1">248566</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33361">33361</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://mail.opensolaris.org/pipermail/onnv-notify/2008-October/015342.html">[onnv-notify] 20081021 6300710 recursive mutex_enter in nfs4rename_persistent_fh()</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in the nfs4rename_persistent_fh function in the NFS 4 (aka NFSv4) client in the kernel in Sun Solaris 10 and OpenSolaris before snv_102 allows local users to cause a denial of service (recursive mutex_enter and panic) via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0043">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ca:service_level_management:3.5" />
                <cpe-lang:fact-ref name="cpe:/a:ca:service_metric_analysis:r11.0" />
                <cpe-lang:fact-ref name="cpe:/a:ca:service_metric_analysis:r11.1" />
                <cpe-lang:fact-ref name="cpe:/a:ca:service_metric_analysis:r11.1:sp1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ca:service_metric_analysis:r11.1:sp1</vuln:product>
            <vuln:product>cpe:/a:ca:service_level_management:3.5</vuln:product>
            <vuln:product>cpe:/a:ca:service_metric_analysis:r11.1</vuln:product>
            <vuln:product>cpe:/a:ca:service_metric_analysis:r11.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0043</vuln:cve-id>
        <vuln:published-datetime>2009-01-08T14:30:11.250-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-12T01:56:24.920-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T08:47:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=196148">https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=196148</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33161">33161</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/499857/100/0/threaded">20090107 CA20090107-01: CA Service Metric Analysis and CA Service Level Management smmsnmpd Arbitrary Command Execution Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0053">ADV-2009-0053</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4887">4887</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/07.aspx">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/07.aspx</vuln:reference>
        </vuln:references>
        <vuln:summary>The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which allows remote attackers to execute arbitrary commands via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0070">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apple:safari" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apple:safari</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0070</vuln:cve-id>
        <vuln:published-datetime>2009-01-08T14:30:11.280-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:00:57.390-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T09:01:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-189" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/48214">safari-array-memory-disclosure(48214)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7673">7673</vuln:reference>
        </vuln:references>
        <vuln:summary>Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array in a JavaScript function, possibly a related issue to CVE-2008-2307.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0071">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:alpha" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:beta5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:alpha</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0:beta2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0071</vuln:cve-id>
        <vuln:published-datetime>2009-01-08T14:30:11.297-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-03-25T01:49:27.267-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>2.6</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T10:12:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=472507">https://bugzilla.mozilla.org/show_bug.cgi?id=472507</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=456727">https://bugzilla.mozilla.org/show_bug.cgi?id=456727</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=448329">https://bugzilla.mozilla.org/show_bug.cgi?id=448329</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33154">33154</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/8219">8219</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/8091">8091</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0224.html">20090107 Re: Firefox 3.0.5 remote vulnerability via queryCommandState</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0223.html">20090107 Re: Firefox 3.0.5 remote vulnerability via queryCommandState</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0220.html">20090107 Firefox 3.0.5 remote vulnerability via queryCommandState</vuln:reference>
        </vuln:references>
        <vuln:summary>Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call.  NOTE: it was later reported that 3.0.6 and 3.0.7 are also affected.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0072">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6:sp1" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6:sp2" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8:beta1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:internet_explorer:6:sp2</vuln:product>
            <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
            <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
            <vuln:product>cpe:/a:microsoft:internet_explorer:6:sp1</vuln:product>
            <vuln:product>cpe:/a:microsoft:internet_explorer:8:beta2</vuln:product>
            <vuln:product>cpe:/a:microsoft:internet_explorer:8:beta1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0072</vuln:cve-id>
        <vuln:published-datetime>2009-01-08T14:30:11.313-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-09T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T10:49:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47788">ie-javascript-screen-dos(47788)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33149">33149</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://skypher.com/index.php/2009/01/07/msie-screen-null-ptr-dos-details/">http://skypher.com/index.php/2009/01/07/msie-screen-null-ptr-dos-details/</vuln:reference>
        </vuln:references>
        <vuln:summary>Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application crash) via an onload=screen[""] attribute value in a BODY element.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0103">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:playsms:playsms:0.9.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:playsms:playsms:0.9.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0103</vuln:cve-id>
        <vuln:published-datetime>2009-01-09T13:30:03.047-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:00:58.250-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T15:02:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-94" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33138">33138</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7687">7687</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4888">4888</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33386">33386</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_path[plug] parameter to plugin/gateway/gnokii/init.php, the (2) apps_path[themes] parameter to plugin/themes/default/init.php, and the (3) apps_path[libs] parameter to lib/function.php.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0104">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:se-ed:ezpack:4.2:beta2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:se-ed:ezpack:4.2:beta2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0104</vuln:cve-id>
        <vuln:published-datetime>2009-01-09T13:30:03.063-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:00:58.390-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T15:04:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33131">33131</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7680">7680</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4890">4890</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via the qType parameter in a webboard prog action.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0105">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:se-ed:ezpack:4.2:beta2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:se-ed:ezpack:4.2:beta2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0105</vuln:cve-id>
        <vuln:published-datetime>2009-01-09T13:30:03.077-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:00:58.610-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T15:15:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33131">33131</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7680">7680</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4890">4890</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd parameter in a prog action.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0106">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpauctions:phpauctions:_nil_" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpauctions:phpauctions:_nil_</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0106</vuln:cve-id>
        <vuln:published-datetime>2009-01-09T13:30:03.093-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-04-10T01:32:32.157-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T15:35:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/43264">phpauctions-profile-sql-injection(43264)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33115">33115</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33331">33331</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/51144">51144</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://milw0rm.com/exploits/7672">7672</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0107">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpauctions:phpauctions:_nil_" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpauctions:phpauctions:_nil_</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0107</vuln:cve-id>
        <vuln:published-datetime>2009-01-09T13:30:03.127-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-09T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T15:47:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33115">33115</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33331">33331</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/51145">51145</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://milw0rm.com/exploits/7672">7672</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0108">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:phpauctions:phpauctions:_nil_" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:phpauctions:phpauctions:_nil_</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0108</vuln:cve-id>
        <vuln:published-datetime>2009-01-09T13:30:03.140-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T16:10:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33120">33120</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7674">7674</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4891">4891</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33331">33331</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/51146">51146</vuln:reference>
        </vuln:references>
        <vuln:summary>PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID, (2) PHPAUCTION_RM_NAME, (3) PHPAUCTION_RM_USERNAME, and (4) PHPAUCTION_RM_EMAIL cookies.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0109">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.61" />
                <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.60" />
                <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.52" />
                <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.51:beta" />
                <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:.05" />
                <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:riotpix:riotpix:0.60</vuln:product>
            <vuln:product>cpe:/a:riotpix:riotpix:0.52</vuln:product>
            <vuln:product>cpe:/a:riotpix:riotpix:0.61</vuln:product>
            <vuln:product>cpe:/a:riotpix:riotpix:0.5</vuln:product>
            <vuln:product>cpe:/a:riotpix:riotpix:.05</vuln:product>
            <vuln:product>cpe:/a:riotpix:riotpix:0.51:beta</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0109</vuln:cve-id>
        <vuln:published-datetime>2009-01-09T13:30:03.157-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:00:59.250-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T16:15:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33132">33132</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7682">7682</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4892">4892</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33395">33395</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.  NOTE: some of these details are obtained from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0110">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.61" />
                <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.60" />
                <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.52" />
                <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.51:beta" />
                <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:.05" />
                <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:riotpix:riotpix:0.60</vuln:product>
            <vuln:product>cpe:/a:riotpix:riotpix:0.52</vuln:product>
            <vuln:product>cpe:/a:riotpix:riotpix:0.61</vuln:product>
            <vuln:product>cpe:/a:riotpix:riotpix:0.5</vuln:product>
            <vuln:product>cpe:/a:riotpix:riotpix:.05</vuln:product>
            <vuln:product>cpe:/a:riotpix:riotpix:0.51:beta</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0110</vuln:cve-id>
        <vuln:published-datetime>2009-01-09T13:30:03.170-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:00:59.467-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T16:38:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33129">33129</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7679">7679</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4893">4893</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33395">33395</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0111">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:goople_cms:goople_cms:1.8.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:goople_cms:goople_cms:1.8.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0111</vuln:cve-id>
        <vuln:published-datetime>2009-01-09T13:30:03.203-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:00:59.640-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T16:49:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33135">33135</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7683">7683</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4894">4894</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33393">33393</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0112">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:expinion:poll_pro:3.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:expinion:poll_pro:3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0112</vuln:cve-id>
        <vuln:published-datetime>2009-01-09T13:30:03.217-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:00:59.860-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T17:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-352" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47754">pollpro-unspecified-csrf(47754)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4895">4895</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33319">33319</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=123117044713213&amp;w=2">20090103 PollPro 3.0 XSRF VuLn</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site request forgery (CSRF) vulnerability in admin/agent_edit.asp in PollPro 3.0 allows remote attackers to create or modify accounts as administrators via the username, password, and name parameters.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0113">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:joomla:xstandard" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.6" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.9" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.8" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.7" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.6" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.5" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.4" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.3" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.2" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.12" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.14" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.11" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.13" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.10" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.1" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.0" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.03" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.1" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.2" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.3" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.4" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.5" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.8" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.0:beta" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.0:rc1" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.0:beta1" />
                    <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.0:beta2" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:joomla:xstandard</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0113</vuln:cve-id>
        <vuln:published-datetime>2009-01-09T13:30:03.233-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:01:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-09T17:02:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33143">33143</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7691">7691</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4896">4896</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33377">33377</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the X_CMS_LIBRARY_PATH HTTP header.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0024">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.15.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.14.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.13.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.11.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.0" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.2.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.49" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.48" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.47" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.46" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.45" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.33" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.34" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.35" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.29" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.30" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.31" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.32" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.41" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.42" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.43" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.44" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.37" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.38" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.39" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.40" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.61" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.62" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.17.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.52" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.51" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.50" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.60" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.59" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.58" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.57" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.56" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.55" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.54" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.16.53" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22_rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22_rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.35</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.38</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.37</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.39</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.30</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.31</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.32</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.33</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.34</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.49</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.48</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22_rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.47</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.46</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.40</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22_rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.41</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.44</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.45</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.42</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.43</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.0</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.29</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.2.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.61</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.60</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.62</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.52</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.51</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.50</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.56</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.55</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.54</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.53</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.59</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.57</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.16.58</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.12.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.15.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.11.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0024</vuln:cve-id>
        <vuln:published-datetime>2009-01-13T12:00:01.170-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-13T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-13T14:16:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33211">33211</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://openwall.com/lists/oss-security/2009/01/12/1">[oss-security] 20090112 CVE-2009-0024 kernel: local privilege escalation in sys_remap_file_pages</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.24.y.git;a=commit;h=8a459e44ad837018ea5c34a9efe8eb4ad27ded26">http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.24.y.git;a=commit;h=8a459e44ad837018ea5c34a9efe8eb4ad27ded26</vuln:reference>
        </vuln:references>
        <vuln:summary>The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denial of service or gain privileges via unspecified vectors, related to the vm_file structure member, and the mmap_region and do_munmap functions.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0041">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.12" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.12.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.11:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.10:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.12.1:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.12:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.14:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.13:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.14" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.13" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.11" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.10" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0beta2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0beta1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.21.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.20" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.16:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.15:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.19:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.17:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.20:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.2:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.21.1:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.21:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.18:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.22" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.19" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.21" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.18" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.17" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.22:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.16" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.15" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.26.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.26.2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.28" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.30.3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.30.2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.30" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.27" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.26" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.29" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.24" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.25" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.3:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.23" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.26.2:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.26.1:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.26:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.25:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.24:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.23:netsec" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.30.4" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.16" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.18.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.17" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.0" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.10.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.12.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.16.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.16.2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.15" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.14" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.13" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.12" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.18" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.11" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.0:beta4" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.10" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.0:beta3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.0:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.7.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4_revision_95946" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.9" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19:rc4" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.8" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.7" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19:rc3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.5" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.6" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.4" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4beta" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19.2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.20" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.20:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.20:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.20:rc3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.21" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.21:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.21:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.21.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.21.2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.22" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.22:rc3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.22:rc4" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.22.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.22.2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.23" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.23:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.23:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.23:rc3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta7" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta7.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta8" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta9" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:rc4" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:rc5" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:rc6" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0.3:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta4" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta5" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:a" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.3.5" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.3.6" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.5.0" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.1.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.1.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:c.1.0:beta7" />
                <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:c.1.0:beta8" />
                <cpe-lang:fact-ref name="cpe:/h:asterisk:s800i_appliance:1.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.12.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.0:beta1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.0:beta2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.15:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.12.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.10.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.23:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:c.1.0:beta8</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.16.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:c.1.0:beta7</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.19:rc4</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.19:rc3</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.19:rc2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.19:rc1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.14:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.22:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.16.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.19</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.18</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.17</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.16</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.20:rc2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.17:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.15</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.20:rc3</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.14</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.13</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.20:rc1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.12</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.11</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.30</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.10</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.21.1:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0.3:rc1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.10:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.26.1:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.0:rc2</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.2.0</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.30.3</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.0:beta4</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.2.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.30.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.16:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.0:beta3</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.12.1:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.23</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.30.4</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.0:rc1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.20</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.21:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.22</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.2:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.21</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4beta</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.26.2:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.3</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.0</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.26.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.26.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.0:beta2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.19</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.18</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.0</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.11:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.3</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.4</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.5</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.6</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.3:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.18:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta7.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.10</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.8</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.11</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.7</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.12</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.13</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.9</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.14</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.15</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.16</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.17</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.20:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.29</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.26:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.1.3.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.1.3.3</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:a</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0.3</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4_revision_95946</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.20</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.23</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.24</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.21</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.22</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.21:rc2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.27</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.21:rc1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.28</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.25</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.26</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta9</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.5.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.7.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.5.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.13:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.5.3</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.23:rc1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.23:rc2</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.5.0</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.23:rc3</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.25:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0:rc4</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0:rc5</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0:rc6</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.22:rc4</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.22:rc3</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.19.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.19.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.12:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.0beta1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.0beta2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.18.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.3.4</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.3.3</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.3.6</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.3.5</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.22.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.21.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.22.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.3.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.24:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.3.1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta7</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.2.19:netsec</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta8</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.21.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta5</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.4.21.1</vuln:product>
            <vuln:product>cpe:/h:asterisk:s800i_appliance:1.2</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta3</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta4</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta1</vuln:product>
            <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0041</vuln:cve-id>
        <vuln:published-datetime>2009-01-14T18:30:00.187-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-05-12T01:36:31.467-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-15T09:43:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-200" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33174">33174</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021549">1021549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/499884/100/0/threaded">20090108 AST-2009-001: Information leak in IAX2 authentication</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0063">ADV-2009-0063</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4910">4910</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200905-01.xml">GLSA-200905-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34982">34982</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33453">33453</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://downloads.digium.com/pub/security/AST-2009-001.html">http://downloads.digium.com/pub/security/AST-2009-001.html</vuln:reference>
        </vuln:references>
        <vuln:summary>IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0119">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0119</vuln:cve-id>
        <vuln:published-datetime>2009-01-14T18:30:04.377-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:01:00.217-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-15T09:54:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33204">33204</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7720">7720</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4912">4912</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0120">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:ibm:websphere_datapower_xml_security_gateway_xs40:3.6.1.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:ibm:websphere_datapower_xml_security_gateway_xs40:3.6.1.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0120</vuln:cve-id>
        <vuln:published-datetime>2009-01-14T19:30:00.280-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:01:00.390-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-15T10:53:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021547">1021547</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33169">33169</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/499870/100/0/threaded">20090108 [IBM Datapower XS40] Denial of Service</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0111">ADV-2009-0111</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4911">4911</vuln:reference>
        </vuln:references>
        <vuln:summary>The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0121">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:goople_cms:goople_cms:1.8.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:goople_cms:goople_cms:1.8.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0121</vuln:cve-id>
        <vuln:published-datetime>2009-01-14T19:30:00.327-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-15T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-15T11:05:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-89" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33393">33393</vuln:reference>
        </vuln:references>
        <vuln:summary>SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0029">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23_rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24_rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24_rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22_rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22_rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24_rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.2.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.12::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.11::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.8::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.7::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.6::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.4::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.3::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.10::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.1::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.9::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.8::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22_rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22_rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.10::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.7::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.9::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23_rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.6::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.11::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24_rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24_rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.4::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.3::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24_rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.12::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.2::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.1::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.2.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.5::x86_64</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0029</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.467-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-06-20T01:26:00.717-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-15T16:14:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01045.html">FEDORA-2009-0816</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=479969">https://bugzilla.redhat.com/show_bug.cgi?id=479969</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33275">33275</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135">MDVSA-2009:135</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2009/dsa-1794">DSA-1794</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2009/dsa-1787">DSA-1787</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2009/dsa-1749">DSA-1749</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35011">35011</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34981">34981</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34394">34394</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33674">33674</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33477">33477</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=linux-kernel&amp;m=123155111608910&amp;w=2">[linux-kernel] 20090110 Re: [PATCH -v7][RFC]: mutex: implement adaptive spinning</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html">SUSE-SA:2009:010</vuln:reference>
        </vuln:references>
        <vuln:summary>The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, sparc64, and mips 64-bit platforms requires that a 32-bit argument in a 64-bit register was properly sign extended when sent from a user-mode application, but cannot verify this, which allows local users to cause a denial of service (crash) or possibly gain privileges via a crafted system call.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0122">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:hp:hplip:2.7.7" />
                <cpe-lang:fact-ref name="cpe:/a:hp:hplip:2.8.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:hp:hplip:2.8.2</vuln:product>
            <vuln:product>cpe:/a:hp:hplip:2.7.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0122</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.483-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-31T01:54:38.047-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.9</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T09:36:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33249">33249</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://launchpad.net/bugs/191299">https://launchpad.net/bugs/191299</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-708-1">USN-708-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33539">33539</vuln:reference>
        </vuln:references>
        <vuln:summary>hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP installation or upgrade by an administrator, related to the product's attempt to correct the ownership of its configuration files within home directories.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0123">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:apple:safari" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/o:microsoft:windows" />
                    <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apple:safari</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0123</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.500-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-22T01:46:15.797-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.1</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T09:51:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-200" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47917">safari-rss-feed-info-disclosure(47917)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021581">1021581</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33234">33234</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33458">33458</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://isc.sans.org/diary.html?storyid=5689">http://isc.sans.org/diary.html?storyid=5689</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://brian.mastenbrook.net/display/27">http://brian.mastenbrook.net/display/27</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for RSS feeds.  NOTE: as of 20090114, the only disclosure is a vague pre-advisory. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0124">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:arrl:tqsllib:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:arrl:tqsllib:2.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0124</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.530-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-06T02:05:51.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T10:14:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00557.html">FEDORA-2009-0543</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=479650">https://bugzilla.redhat.com/show_bug.cgi?id=479650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33543">33543</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://openwall.com/lists/oss-security/2009/01/12/4">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511509">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511509</vuln:reference>
        </vuln:references>
        <vuln:summary>The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0125">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:finkproject:libnasl:2.2.11" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:finkproject:libnasl:2.2.11</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0125</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.547-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-10T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T10:42:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=479655">https://bugzilla.redhat.com/show_bug.cgi?id=479655</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VIM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.attrition.org/pipermail/vim/2009-January/002133.html">20090120 CVE-2009-0125 (fwd)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://openwall.com/lists/oss-security/2009/01/12/4">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html">SUSE-SR:2009:003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://cvs.fedoraproject.org/viewvc/rpms/libnasl/F-10/libnasl.spec?r1=1.16&amp;r2=1.17">http://cvs.fedoraproject.org/viewvc/rpms/libnasl/F-10/libnasl.spec?r1=1.16&amp;r2=1.17</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511517">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511517</vuln:reference>
        </vuln:references>
        <vuln:summary>** DISPUTED **  NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 does not properly check the return value from the OpenSSL DSA_do_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.  NOTE: the upstream vendor has disputed this issue, stating "while we do misuse this function (this is a bug), it has absolutely no security ramification."</vuln:summary>
    </entry>
    <entry id="CVE-2009-0126">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:berkeley:boinc_client:6.2.14" />
                <cpe-lang:fact-ref name="cpe:/a:berkeley:boinc_client:6.4.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:berkeley:boinc_client:6.4.5</vuln:product>
            <vuln:product>cpe:/a:berkeley:boinc_client:6.2.14</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0126</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.563-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-03-06T01:49:14.547-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T10:51:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00034.html">FEDORA-2009-0578</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=479664">https://bugzilla.redhat.com/show_bug.cgi?id=479664</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33828">33828</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33806">33806</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://openwall.com/lists/oss-security/2009/01/12/4">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html">SUSE-SR:2009:003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://boinc.berkeley.edu/trac/ticket/823">http://boinc.berkeley.edu/trac/ticket/823</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://boinc.berkeley.edu/trac/changeset/16883">http://boinc.berkeley.edu/trac/changeset/16883</vuln:reference>
        </vuln:references>
        <vuln:summary>The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0127">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:heikkitoivonen:m2crypto:_nil_" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:heikkitoivonen:m2crypto:_nil_</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0127</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.577-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-16T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T11:21:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=479676">https://bugzilla.redhat.com/show_bug.cgi?id=479676</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://openwall.com/lists/oss-security/2009/01/12/4">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511515">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511515</vuln:reference>
        </vuln:references>
        <vuln:summary>** DISPUTED ** M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.  NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto."</vuln:summary>
    </entry>
    <entry id="CVE-2009-0128">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:llnl:slurm:_nil_" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:llnl:slurm:_nil_</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0128</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.610-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-16T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T11:26:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://openwall.com/lists/oss-security/2009/01/12/4">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511511">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511511</vuln:reference>
        </vuln:references>
        <vuln:summary>plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0129">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:perl-openssl:libcrypt-openssl-dsa-perl:_nil_" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:perl-openssl:libcrypt-openssl-dsa-perl:_nil_</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0129</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.627-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-16T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T11:33:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://openwall.com/lists/oss-security/2009/01/12/4">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511519">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511519</vuln:reference>
        </vuln:references>
        <vuln:summary>libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0130">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:erlang:erlang:_nil_" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:erlang:erlang:_nil_</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0130</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.640-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-16T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T11:37:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-287" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://openwall.com/lists/oss-security/2009/01/12/4">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511520">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511520</vuln:reference>
        </vuln:references>
        <vuln:summary>** DISPUTED ** lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.  NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus "this report is invalid."</vuln:summary>
    </entry>
    <entry id="CVE-2009-0131">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_29::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_30::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_31::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_32::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_33::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_34::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_35::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_55::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_40::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_54::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_41::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_42::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_43::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_44::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_45::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_46::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_48::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_47::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_50::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_49::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_36::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_52::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_37::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_51::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_38::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_53::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_39::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_68::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_67::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_57::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_56::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_66::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_59::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_65::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_74::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_58::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_64::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_73::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_61::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_63::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_60::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_62::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_75::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_71::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_72::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_70::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_69::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_76::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_77::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_78::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_79::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_80::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_81::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_82::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_83::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_84::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_85::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_86::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_87::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_88::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_89::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_90::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_29::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_30::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_31::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_32::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_33::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_34::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_35::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_40::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_41::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_55::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_42::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_43::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_44::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_45::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_46::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_48::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_47::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_50::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_49::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_36::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_52::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_37::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_51::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_54::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_38::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_53::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_39::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_68::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_67::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_57::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_56::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_66::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_59::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_65::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_74::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_58::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_64::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_73::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_61::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_63::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_60::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_62::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_75::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_71::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_72::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_70::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_69::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_76::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_77::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_78::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_79::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_80::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_81::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_82::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_83::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_84::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_85::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_86::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_87::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_88::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_89::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_90::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:opensolaris:snv_69::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_50::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_65::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_41::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_29::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_48::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_33::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_68::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_37::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_35::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_48::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_30::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_58::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_53::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_36::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_62::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_37::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_81::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_80::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_47::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_34::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_81::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_77::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_46::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_82::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_65::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_44::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_34::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_50::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_32::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_72::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_31::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_90::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_60::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_61::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_64::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_83::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_42::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_74::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_86::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_82::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_84::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_78::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_74::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_32::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_77::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_89::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_63::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_75::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_62::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_55::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_89::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_30::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_71::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_70::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_87::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_58::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_45::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_85::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_55::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_86::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_73::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_79::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_90::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_67::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_88::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_43::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_40::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_56::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_41::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_35::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_29::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_69::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_54::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_76::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_75::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_57::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_83::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_52::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_66::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_51::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_66::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_80::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_51::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_67::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_40::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_68::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_64::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_76::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_38::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_61::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_54::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_71::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_78::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_36::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_52::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_79::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_53::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_59::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_70::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_42::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_31::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_84::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_39::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_85::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_49::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_63::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_46::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_57::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_59::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_87::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_49::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_43::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_47::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_88::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_39::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_72::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_33::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_45::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_44::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_60::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_56::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_38::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_73::x86</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0131</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.657-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-05T01:53:13.453-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.9</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T13:17:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021600">1021600</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33267">33267</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239188-1">239188</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.opensolaris.org/view_bug.do?bug_id=6711995">http://bugs.opensolaris.org/view_bug.do?bug_id=6711995</vuln:reference>
        </vuln:references>
        <vuln:summary>The UFS implementation in the kernel in Sun OpenSolaris snv_29 through snv_90 allows local users to cause a denial of service (panic) via the single posix_fallocate test in the SUSv3 POSIX test suite, related to an F_ALLOCSP fcntl call.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0132">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:::x86" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:solaris:10::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:8::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:9::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:10::sparc</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0132</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.687-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-31T01:54:40.280-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.9</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T14:04:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-189" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33188">33188</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-59-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-59-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trapkit.de/advisories/TKADV2009-001.txt">http://www.trapkit.de/advisories/TKADV2009-001.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021553">1021553</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0099">ADV-2009-0099</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-247986-1">247986</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33516">33516</vuln:reference>
        </vuln:references>
        <vuln:summary>Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via a large integer value in the second argument (aka nent argument).</vuln:summary>
    </entry>
    <entry id="CVE-2009-0133">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:microsoft:html_help_workshop:4.74" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:html_help_workshop:4.74</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0133</vuln:cve-id>
        <vuln:published-datetime>2009-01-15T12:30:00.703-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:01:03.547-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T14:07:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7727">7727</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4914">4914</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0134">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:share2:easy_grid_control:3.51" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:share2:easy_grid_control:3.51</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0134</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T13:30:00.203-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:01:03.767-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-16T16:29:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47946">easygrid-activex-dosavefile-file-overwrite(47946)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33272">33272</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7779">7779</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4913">4913</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33537">33537</vuln:reference>
        </vuln:references>
        <vuln:summary>Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method.  NOTE: vector 1 could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs.  NOTE: some of these details are obtained from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0135">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:amarok:amarok:1.4.10" />
                <cpe-lang:fact-ref name="cpe:/a:amarok:amarok:2.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:amarok:amarok:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:amarok:amarok:2.0</vuln:product>
            <vuln:product>cpe:/a:amarok:amarok:2.0.1</vuln:product>
            <vuln:product>cpe:/a:amarok:amarok:1.4.10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0135</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T13:30:00.233-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-04-02T01:44:04.360-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T10:40:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00708.html">FEDORA-2009-0715</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=479946">https://bugzilla.redhat.com/show_bug.cgi?id=479946</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=479560">https://bugzilla.redhat.com/show_bug.cgi?id=479560</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/USN-739-1">USN-739-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021558">1021558</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33210">33210</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/499984/100/0/threaded">20090111 [TKADV2009-002] Amarok Integer Overflow and Unchecked Allocation Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:030">MDVSA-2009:030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0100">ADV-2009-0100</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2009/dsa-1706">DSA-1706</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://websvn.kde.org/?view=rev&amp;revision=908415">http://websvn.kde.org/?view=rev&amp;revision=908415</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://websvn.kde.org/?view=rev&amp;revision=908401">http://websvn.kde.org/?view=rev&amp;revision=908401</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://websvn.kde.org/?view=rev&amp;revision=908391">http://websvn.kde.org/?view=rev&amp;revision=908391</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://trapkit.de/advisories/TKADV2009-002.txt">http://trapkit.de/advisories/TKADV2009-002.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4915">4915</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200903-34.xml">GLSA-200903-34</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34407">34407</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34315">34315</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33819">33819</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33640">33640</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33522">33522</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33505">33505</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://openwall.com/lists/oss-security/2009/01/14/2">[oss-security] 20090114 CVE Request -- amarok</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html">SUSE-SR:2009:003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.gentoo.org/show_bug.cgi?id=254896">http://bugs.gentoo.org/show_bug.cgi?id=254896</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://amarok.kde.org/en/releases/2.0.1.1">http://amarok.kde.org/en/releases/2.0.1.1</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple integer overflows in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to execute arbitrary code via an Audible Audio (.aa) file with a large (1) nlen or (2) vlen Tag value, each of which triggers a heap-based buffer overflow.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0136">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:amarok:amarok:1.4.10" />
                <cpe-lang:fact-ref name="cpe:/a:amarok:amarok:2.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:amarok:amarok:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:amarok:amarok:2.0</vuln:product>
            <vuln:product>cpe:/a:amarok:amarok:2.0.1</vuln:product>
            <vuln:product>cpe:/a:amarok:amarok:1.4.10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0136</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T13:30:00.250-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-04-02T01:44:04.483-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T10:52:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-189" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00708.html">FEDORA-2009-0715</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=479946">https://bugzilla.redhat.com/show_bug.cgi?id=479946</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=479560">https://bugzilla.redhat.com/show_bug.cgi?id=479560</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/USN-739-1">USN-739-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021558">1021558</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33210">33210</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/499984/100/0/threaded">20090111 [TKADV2009-002] Amarok Integer Overflow and Unchecked Allocation Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:030">MDVSA-2009:030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0100">ADV-2009-0100</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2009/dsa-1706">DSA-1706</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://websvn.kde.org/?view=rev&amp;revision=908415">http://websvn.kde.org/?view=rev&amp;revision=908415</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://websvn.kde.org/?view=rev&amp;revision=908401">http://websvn.kde.org/?view=rev&amp;revision=908401</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://websvn.kde.org/?view=rev&amp;revision=908391">http://websvn.kde.org/?view=rev&amp;revision=908391</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://trapkit.de/advisories/TKADV2009-002.txt">http://trapkit.de/advisories/TKADV2009-002.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4915">4915</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200903-34.xml">GLSA-200903-34</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34407">34407</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34315">34315</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33819">33819</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33640">33640</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33522">33522</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33505">33505</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://openwall.com/lists/oss-security/2009/01/14/2">[oss-security] 20090114 CVE Request -- amarok</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html">SUSE-SR:2009:003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.gentoo.org/show_bug.cgi?id=254896">http://bugs.gentoo.org/show_bug.cgi?id=254896</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://amarok.kde.org/en/releases/2.0.1.1">http://amarok.kde.org/en/releases/2.0.1.1</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple array index errors in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via an Audible Audio (.aa) file with a crafted (1) nlen or (2) vlen Tag value, each of which can lead to an invalid pointer dereference, or the writing of a 0x00 byte to an arbitrary memory location, after an allocation failure.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0053">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.5" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.6" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.5</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.6</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0053</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T16:30:03.407-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-05T01:53:06.687-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T15:04:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-310" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33268">33268</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0140">ADV-2009-0140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1021593">1021593</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33479">33479</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/51395">51395</vuln:reference>
        </vuln:references>
        <vuln:summary>PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to obtain the decryption key via unspecified vectors, related to a "logic error."</vuln:summary>
    </entry>
    <entry id="CVE-2009-0054">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.5" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.6" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.5</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.6</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0054</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T16:30:03.437-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-05T01:53:06.860-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T15:18:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-255" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33268">33268</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0140">ADV-2009-0140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1021593">1021593</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33479">33479</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/51396">51396</vuln:reference>
        </vuln:references>
        <vuln:summary>PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to capture credentials by tricking a user into reading a modified or crafted e-mail message.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0055">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.5" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.6" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.5</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.6</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0055</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T16:30:03.453-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-05T01:53:07.093-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T15:27:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-352" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33268">33268</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0140">ADV-2009-0140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1021594">1021594</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33479">33479</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/51397">51397</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to modify appliance preferences as arbitrary users via unspecified vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0056">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.5" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.6" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.1" />
                <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_postx:6.2.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.5</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.6</vuln:product>
            <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0056</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T16:30:03.467-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-05T01:53:07.280-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T15:30:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-352" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33268">33268</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0140">ADV-2009-0140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1021594">1021594</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33479">33479</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/51398">51398</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to execute commands and modify appliance preferences as arbitrary users via a logout action.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0167">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_61::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_61::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_62::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_62::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_63::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_63::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_64::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_64::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_65::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_65::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_66::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_66::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_67::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_67::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_68::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_68::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_69::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_69::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_70::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_70::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_71::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_71::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_72::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_72::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_73::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_73::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_74::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_74::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_75::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_75::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_76::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_76::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_77::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_77::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_78::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_78::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_79::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_79::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_80::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_80::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_81::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_81::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_82::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_82::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_83::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_83::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_84::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_84::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_85::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_85::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_86::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_86::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_87::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_87::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_88::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_88::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_89::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_89::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_90::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_90::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_91::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_91::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_92::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_92::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_93::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_93::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_94::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_94::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_95::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_95::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_96::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_96::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_97::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_97::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_98::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_98::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_99::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_100::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_99::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_100::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_101::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_102::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_103::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_104::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_105::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_106::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_101::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_102::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_103::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_104::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_105::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_106::sparc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:opensolaris:snv_105::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_86::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_73::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_79::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_90::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_69::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_67::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_88::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_65::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_92::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_94::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_91::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_98::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_69::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_93::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_68::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_76::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_75::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_101::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_83::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_66::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_103::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_93::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_62::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_95::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_66::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_80::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_81::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_67::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_68::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_97::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_80::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_81::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_64::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:10.0::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_76::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_77::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_82::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_106::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_96::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_65::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_61::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_71::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_78::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_96::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_79::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_95::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_91::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_104::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_72::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_70::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_99::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_100::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_90::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_61::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_99::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_84::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_64::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_83::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_98::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_106::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_74::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_105::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_86::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_82::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_84::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_97::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_92::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_85::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_74::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_78::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_63::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_77::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_89::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_87::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_63::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_88::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_102::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_101::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_100::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_72::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_75::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_62::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_89::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_87::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_71::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_70::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:10.0::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_104::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_103::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_94::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_85::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_102::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_73::x86</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0167</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T16:30:03.483-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-03-04T01:48:33.077-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.7</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T16:01:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:6175" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6175" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139390-01-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139390-01-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021601">1021601</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33269">33269</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0155">ADV-2009-0155</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2009-026.htm">http://support.avaya.com/elmodocs2/security/ASA-2009-026.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249306-1">249306</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33705">33705</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33488">33488</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://opensolaris.org/os/bug_reports/request_sponsor/">http://opensolaris.org/os/bug_reports/request_sponsor/</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in lpadmin in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to enumeration of "wrong printers," aka a "Temporary file vulnerability."</vuln:summary>
    </entry>
    <entry id="CVE-2009-0168">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_61::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_62::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_63::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_68::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_71::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_67::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_72::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_66::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_70::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_65::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_64::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_73::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_69::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_78::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_77::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_79::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_74::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_81::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_80::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_76::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_83::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_75::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_82::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_85::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_84::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_87::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_88::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_86::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_92::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_91::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_90::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_89::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_93::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_99::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_97::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_98::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_96::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_95::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_94::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_100::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_101::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_102::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_103::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_104::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_105::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_106::x86" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_106::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_105::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_104::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_103::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_102::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_101::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_100::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_61::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_62::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_63::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_71::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_68::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_72::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_67::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_70::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_66::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_65::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_64::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_73::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_69::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_78::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_77::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_83::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_79::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_74::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_80::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_76::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_82::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_75::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_81::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_84::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_86::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_85::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_87::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_88::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_89::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_90::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_91::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_92::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_93::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_99::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_98::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_97::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_96::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_94::sparc" />
                <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_95::sparc" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:sun:opensolaris:snv_86::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_105::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_73::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_79::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_90::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_69::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_67::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_88::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_65::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_92::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_94::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_91::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_98::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_69::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_93::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_68::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_76::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_75::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_83::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_101::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_66::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_103::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_62::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_93::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_66::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_95::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_81::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_80::x86</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:10::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_67::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_68::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_80::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_97::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_81::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_64::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_76::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_77::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_82::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_106::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_65::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_96::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_61::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_71::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_78::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_96::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_79::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_95::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_91::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_72::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_104::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_70::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_99::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_100::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_90::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_61::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_99::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_84::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_83::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_64::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_98::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_106::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_74::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_105::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_84::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_82::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_86::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_97::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_92::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_74::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_78::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_85::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_63::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_77::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_87::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_89::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_63::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_88::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_101::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_102::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_100::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_75::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_72::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_62::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_89::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:solaris:10::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_87::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_70::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_71::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_104::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_85::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_103::sparc</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_94::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_73::x86</vuln:product>
            <vuln:product>cpe:/o:sun:opensolaris:snv_102::x86</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0168</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T16:30:03.517-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-03-04T01:48:33.203-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.9</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T16:41:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:5503" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5503" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249306-1">249306</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139390-01-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139390-01-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/48143">solaris-ppdmgr-dos(48143)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021601">1021601</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33269">33269</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0155">ADV-2009-0155</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2009-026.htm">http://support.avaya.com/elmodocs2/security/ASA-2009-026.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33705">33705</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33488">33488</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://opensolaris.org/os/bug_reports/request_sponsor/">http://opensolaris.org/os/bug_reports/request_sponsor/</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in ppdmgr in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to a failure to "include all cache files," and improper handling of temporary files.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0169">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_access_manager:7.1::windows" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_access_manager:7.1::solaris_x86" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_access_manager:7.1::solaris_sparc" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_access_manager:7.1::linux" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sun:java_system_access_manager:7.1::solaris_sparc</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_access_manager:7.1::linux</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_access_manager:7.1::solaris_x86</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_access_manager:7.1::windows</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0169</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T16:30:03.530-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:01:04.640-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T16:36:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33266">33266</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47944">sun-jsam-subrealm-privilege-escalation(47944)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021604">1021604</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0157">ADV-2009-0157</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249106-1">249106</vuln:reference>
        </vuln:references>
        <vuln:summary>Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin account in the sub-realm, and then logging in as amadmin in the root realm.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0170">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_access_manager:7.0_2005q4" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_access_manager:6.3_2005q4" />
                <cpe-lang:fact-ref name="cpe:/a:sun:java_system_access_manager:7.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sun:java_system_access_manager:7.0_2005q4</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_access_manager:7.1</vuln:product>
            <vuln:product>cpe:/a:sun:java_system_access_manager:6.3_2005q4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0170</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T16:30:03.547-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-05T01:53:15.233-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T14:12:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-264" />
        <vuln:cwe id="CWE-255" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33265">33265</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-242166-1">242166</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47942">sun-jsam-password-info-disclosure(47942)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021605">1021605</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0156">ADV-2009-0156</vuln:reference>
        </vuln:references>
        <vuln:summary>Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obtain unspecified other "access to resources," by visiting the Configuration Items component in the console.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0171">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/h:sun:sparc_enterprise_server:m4000" />
                <cpe-lang:fact-ref name="cpe:/h:sun:sparc_enterprise_server:m5000" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/h:sun:sparc_enterprise_server:m5000</vuln:product>
            <vuln:product>cpe:/h:sun:sparc_enterprise_server:m4000</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0171</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T16:30:03.563-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-05T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T13:34:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021602">1021602</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33280">33280</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0207">ADV-2009-0207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249126-1">249126</vuln:reference>
        </vuln:references>
        <vuln:summary>The Sun SPARC Enterprise M4000 and M5000 Server, within a certain range of serial numbers, allows remote attackers to use the manufacturing root password, perform a root login to the eXtended System Control Facility Unit (aka XSCFU or Service Processor), and have unspecified other impact.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0172">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1::aix" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1::hp-ux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1::linux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1::solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1::windows" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp2:aix" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp2:hp-ux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp2:linux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp2:solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp2:windows" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp3:aix" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp3:hp-ux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp3:solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4:aix" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4:hp-ux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4:linux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4:windows" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4a:hp-ux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4a:linux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4a:windows" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:ga" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5::aix" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5::hp-ux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5::linux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5::solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5::windows" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5:fp1:aix" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5:fp1:linux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5:fp1:windows" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5:fp1:solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5:fp1:hp-ux" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp2:linux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5:fp1:linux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4:aix</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4:linux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4a:linux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5::windows</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5:fp1:solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1::hp-ux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp2</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1::windows</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1::solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4a:windows</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5:fp1:aix</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp2:aix</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4:hp-ux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:ga</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp2:hp-ux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp3:solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5:fp1:windows</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp2:windows</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5::hp-ux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1::aix</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4a</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5:fp1:hp-ux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4:windows</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5::solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5::linux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5::aix</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp2:solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp3:hp-ux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1::linux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp3:aix</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4a:hp-ux</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0172</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T16:30:03.593-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-06-05T01:26:09.390-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T13:25:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33258">33258</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-01.ibm.com/support/docview.wss?uid=swg21363936">http://www-01.ibm.com/support/docview.wss?uid=swg21363936</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47931">ibm-db2-connect-stream-dos(47931)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0137">ADV-2009-0137</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-01.ibm.com/support/docview.wss?uid=swg1IZ37696">IZ37696</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1021591">1021591</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33529">33529</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0173">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1::aix" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1::hp-ux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1::linux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1::solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1::windows" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp2" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp2:aix" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp2:hp-ux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp2:linux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp2:solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp2:windows" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp3:aix" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp3:hp-ux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp3:solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4:aix" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4:hp-ux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4:linux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4:windows" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4a" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4a:hp-ux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4a:linux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:fp4a:windows" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:ga" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5::aix" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5::hp-ux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5::linux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5::solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5::windows" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5:fp1:aix" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5:fp1:linux" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5:fp1:windows" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5:fp1:solaris" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.5:fp1:hp-ux" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp2:linux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5:fp1:linux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4:aix</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4:linux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4a:linux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5::windows</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5:fp1:solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1::hp-ux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp2</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1::windows</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1::solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4a:windows</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5:fp1:aix</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp2:aix</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4:hp-ux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:ga</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp2:hp-ux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp3:solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5:fp1:windows</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp2:windows</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5::hp-ux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1::aix</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4a</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5:fp1:hp-ux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4:windows</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5::solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5::linux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.5::aix</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp2:solaris</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp3:hp-ux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1::linux</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp3:aix</vuln:product>
            <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:fp4a:hp-ux</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0173</vuln:cve-id>
        <vuln:published-datetime>2009-01-16T16:30:03.610-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-06-05T01:26:09.517-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-19T13:09:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-01.ibm.com/support/docview.wss?uid=swg21363936">http://www-01.ibm.com/support/docview.wss?uid=swg21363936</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47934">ibm-db2-datastream-dos(47934)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33258">33258</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0137">ADV-2009-0137</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-01.ibm.com/support/docview.wss?uid=swg1IZ39652">IZ39652</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1021591">1021591</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33529">33529</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0174">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.49" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.49</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0174</vuln:cve-id>
        <vuln:published-datetime>2009-01-20T11:00:08.967-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:01:05.547-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-20T12:11:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47851">vuplayer-asx-bo(47851)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33185">33185</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7715">7715</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7714">7714</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7713">7713</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7709">7709</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4918">4918</vuln:reference>
        </vuln:references>
        <vuln:summary>Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF element in a .asx file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0175">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:heathcosoft:mp3_trackmaker:1.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:heathcosoft:mp3_trackmaker:1.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0175</vuln:cve-id>
        <vuln:published-datetime>2009-01-20T11:00:08.983-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:01:05.750-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-20T12:15:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/47852">mp3trackmaker-mp3-bo(47852)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33183">33183</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7708">7708</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4920">4920</vuln:reference>
        </vuln:references>
        <vuln:summary>Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an invalid .mp3 file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0176">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_professional_software:4.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_unite:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_unite:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_unite:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_unite:1.0.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.3</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.4</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_professional_software:4.1.4</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_unite:1.0.1</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_unite:1.0.2</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_unite:1.0.3</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_unite:1.0</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.5</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0176</vuln:cve-id>
        <vuln:published-datetime>2009-01-20T11:00:09.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-05-18T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-20T12:34:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33224">33224</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17119">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17119</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33534">33534</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=765">20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'bitmaps' Heap Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=764">20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'symWidths' Heap Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to "symWidths"; or (2) a crafted data stream in a .pdf file, related to "bitmaps."</vuln:summary>
    </entry>
    <entry id="CVE-2009-0177">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:6.51" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:6.5" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:6.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:6.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:6.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:6.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:6.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:5.5.2" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:5.5.4" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:5.5.0" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:5.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:5.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:5.5.8" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:5.5.5" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:5.5.6" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:5.5.7" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:4.5.3" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:2.5.1" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:2.5" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:2.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:2.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:2.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:2.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:2.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:1.05" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:1.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:1.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:1.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:1.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:1.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:1.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_player:1.0.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:vmware:vmware_workstation:5.5.8</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:4.5.3</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:2.5</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:6.0.4</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:6.0.5</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:2.0</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:1.05</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:5.5.5</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:5.5.4</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:5.5.7</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:5.5.6</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:5.5.1</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:6.0.2</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:5.5.0</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:6.0.3</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:5.5.3</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:5.5.2</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:6.0.1</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:2.0.1</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:5.0</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:2.5.1</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:2.0.3</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:2.0.2</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:6.5</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:2.0.5</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:2.0.4</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:6.0</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:1.0.6</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:1.0.8</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:1.0.7</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:1.0.9</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:1.0.0</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:1.0.2</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:1.0.1</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_workstation:6.51</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:1.0.4</vuln:product>
            <vuln:product>cpe:/a:vmware:vmware_player:1.0.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0177</vuln:cve-id>
        <vuln:published-datetime>2009-01-20T11:00:09.030-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-04-23T00:00:00.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-20T12:37:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/security/advisories/VMSA-2009-0005.html">http://www.vmware.com/security/advisories/VMSA-2009-0005.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0024">ADV-2009-0024</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://seclists.org/fulldisclosure/2009/Apr/0036.html">20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.vmware.com/pipermail/security-announce/2009/000054.html">[security-announce] 20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/0944">ADV-2009-0944</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021512">1021512</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/34373">34373</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34601">34601</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33372">33372</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/51180">51180</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://milw0rm.com/exploits/7647">7647</vuln:reference>
        </vuln:references>
        <vuln:summary>vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1 build 156745; and VMware Fusion before 2.0.2 build 147997 allows remote attackers to cause a denial of service (daemon crash) via a long (1) USER or (2) PASS command.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0178">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ibm:hardware_management_console:7.3.2.0:sp1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:hardware_management_console:7.3.2.0:sp1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0178</vuln:cve-id>
        <vuln:published-datetime>2009-01-20T11:30:00.420-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-26T14:24:26.807-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-21T09:36:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/48010">ibm-hmc-unspecified(48010)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4521">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4521</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33293">33293</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0158">ADV-2009-0158</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33518">33518</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/51432">51432</vuln:reference>
        </vuln:references>
        <vuln:summary>Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0179">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.9-1" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.9-2" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.9-3" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.9-4" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.9-5" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.9-6" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.10-1" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.10-2" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.10-3" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.10-4" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.10-5" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.11-1" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.11-2" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.11-3" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.11-4" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.11-5" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.11-6" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.1.12" />
                <cpe-lang:fact-ref name="cpe:/a:igno_saitz:libmikmod:3.2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.9-5</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.9-6</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.9-3</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.12</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.9-4</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.10-5</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.9-1</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.10-4</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.9-2</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.10-3</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.11-1</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.10-2</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.11-2</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.11-3</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.10-1</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.11-4</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.11-5</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.1.11-6</vuln:product>
            <vuln:product>cpe:/a:igno_saitz:libmikmod:3.2.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0179</vuln:cve-id>
        <vuln:published-datetime>2009-01-20T11:30:00.453-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-09-02T01:20:21.140-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-21T09:44:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01312.html">FEDORA-2009-9112</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01305.html">FEDORA-2009-9095</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=479833">https://bugzilla.redhat.com/show_bug.cgi?id=479833</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33240">33240</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34259">34259</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://openwall.com/lists/oss-security/2009/01/13/2">[oss-security] 20090113 CVE Request -- libmikmod</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html">SUSE-SR:2009:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476339">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476339</vuln:reference>
        </vuln:references>
        <vuln:summary>libmikmod 3.1.11 through 3.2.0, as used by MikMod and possibly other products, allows user-assisted attackers to cause a denial of service (application crash) by loading an XM file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0180">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:0.3.1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:0.2.1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:0.3.3" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:0.2" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.6" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.2" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.4" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.3" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.8" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.7:pre-2" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.7:pre-1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.7" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.8:rc-4" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.8:rc-3" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.8:rc-2" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.8:rc-1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.12" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.11" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.10" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.9" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.1.1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.1.0:rc-1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.1.2" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/o:redhat:fedora:9" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:0.3.1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:0.2.1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:0.3.3" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:0.2" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.6" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.2" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.4" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.3" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.8" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.7:pre-2" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.7:pre-1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.7" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.8:rc-4" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.8:rc-3" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.8:rc-2" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.8:rc-1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.12" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.11" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.10" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.0.9" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.1.2" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.1.1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.1.0:rc-1" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.1.3" />
                    <cpe-lang:fact-ref name="cpe:/a:nfs:nfs-utils:1.1.4" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/o:redhat:fedora:10" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.10</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.11</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.8:rc-3</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.1.1</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.8:rc-4</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.1.0</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.1.3</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.8:rc-1</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.1.2</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.8:rc-2</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.12</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.1.4</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.7:pre-1</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:0.3.3</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:0.3.1</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:0.2.1</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.1.0:rc-1</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.7:pre-2</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:0.2</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.6</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.3</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.4</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.1</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.2</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.9</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.7</vuln:product>
            <vuln:product>cpe:/a:nfs:nfs-utils:1.0.8</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0180</vuln:cve-id>
        <vuln:published-datetime>2009-01-20T11:30:00.467-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-21T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-21T09:49:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00526.html">FEDORA-2009-0297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00376.html">FEDORA-2009-0266</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=477864">https://bugzilla.redhat.com/show_bug.cgi?id=477864</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/48058">nfsutils-tcpwrapper-security-bypass(48058)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33294">33294</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33545">33545</vuln:reference>
        </vuln:references>
        <vuln:summary>Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions, possibly a related issue to CVE-2008-1376.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0181">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:vuplayer:vuplayer</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0181</vuln:cve-id>
        <vuln:published-datetime>2009-01-20T11:30:00.483-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:01:06.877-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-21T09:55:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/48169">vuplayer-file-bo(48169)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/499810/100/0/threaded">20090106 VUPLAYER BufferOver flow POC</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4921">4921</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in VUPlayer allows user-assisted attackers to have an unknown impact via a long file, as demonstrated by a file composed entirely of 'A' characters.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0182">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.49" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.48" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.47" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.46" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.45" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.44" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.43" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.42" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.41" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.4" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.3" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.23" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.22" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.21" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.11" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.1" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.03" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.02" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.01" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.9" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.8" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.7" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.6" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.5" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.4" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.2" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.05" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.04" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.01" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:0.9" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:0.8" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:0.7" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:0.6" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:0.5" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:0.4" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:0.3" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:0.2" />
                <cpe-lang:fact-ref name="cpe:/a:vuplayer:vuplayer:0.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.11</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.04</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.01</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.7</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.8</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.9</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.3</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.4</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.5</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.1</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.0</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.6</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.3</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.0</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.2</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.1</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.2</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.4</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:0.1</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.22</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.41</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.23</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:0.3</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.02</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:0.2</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.21</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.03</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:0.5</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:0.4</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.01</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:0.7</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:0.6</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:0.9</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.49</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:0.8</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.48</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.47</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.46</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.45</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.44</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.43</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:2.42</vuln:product>
            <vuln:product>cpe:/a:vuplayer:vuplayer:1.05</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0182</vuln:cve-id>
        <vuln:published-datetime>2009-01-20T11:30:00.500-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-01-29T02:01:07.063-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-21T09:59:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/48170">vuplayer-fileline-bo(48170)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/7695">7695</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4923">4923</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL on a File1 line.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0219">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_professional_software:4.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_unite:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_unite:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_unite:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:research_in_motion_limited:blackberry_unite:1.0.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.3</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.4</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_professional_software:4.1.4</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_unite:1.0.1</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_unite:1.0.2</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_unite:1.0.3</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_unite:1.0</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.5</vuln:product>
            <vuln:product>cpe:/a:research_in_motion_limited:blackberry_enterprise_server:4.1.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2009-0219</vuln:cve-id>
        <vuln:published-datetime>2009-01-20T20:30:00.343-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-02-05T01:53:18.063-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2009-01-21T09:34:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021559">1021559</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33250">33250</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17119">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17119</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33534">33534</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>IDEFENSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=766">20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller Uninitialized Memory Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:summary>The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted data stream in a .pdf file.</vuln:summary>
    </entry>
    <entry id="CVE-2009-0031">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23_rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24_rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24_rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2