<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" nvd_xml_version="2.0" pub_date="2013-06-19T05:40:43" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
  <entry id="CVE-2009-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1.70"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:4.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.8</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.6</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1.70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0001</vuln:cve-id>
    <vuln:published-datetime>2009-01-21T15:30:00.250-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:44.360-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-22T09:46:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6135" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6135" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" xml:lang="en">TA09-022A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" xml:lang="en">APPLE-SA-2009-01-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48154" xml:lang="en">quicktime-rtspurl-bo(48154)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0212" xml:lang="en">ADV-2009-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33385" xml:lang="en">33385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3403" xml:lang="en">http://support.apple.com/kb/HT3403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33632" xml:lang="en">33632</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6135" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6135" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted RTSP URL.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1.70"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:4.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.8</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.6</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1.70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0002</vuln:cve-id>
    <vuln:published-datetime>2009-01-21T15:30:00.267-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:44.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-22T09:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5646" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5646" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" xml:lang="en">TA09-022A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" xml:lang="en">APPLE-SA-2009-01-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-09-005/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-09-005/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0212" xml:lang="en">ADV-2009-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33384" xml:lang="en">33384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3403" xml:lang="en">http://support.apple.com/kb/HT3403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33632" xml:lang="en">33632</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51525" xml:lang="en">51525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2009-01/0210.html" xml:lang="en">20090121 ZDI-09-005: Apple QuickTime VR Track Header Atom Heap Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5646" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5646" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QTVR movie file with crafted THKD atoms.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1.70"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:4.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.8</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.6</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1.70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0003</vuln:cve-id>
    <vuln:published-datetime>2009-01-21T15:30:00.280-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-22T09:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6218" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6218" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" xml:lang="en">TA09-022A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" xml:lang="en">APPLE-SA-2009-01-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-09-006/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-09-006/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0212" xml:lang="en">ADV-2009-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33387" xml:lang="en">33387</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3403" xml:lang="en">http://support.apple.com/kb/HT3403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33632" xml:lang="en">33632</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51526" xml:lang="en">51526</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6218" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6218" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via an AVI movie file with an invalid nBlockAlign value in the _WAVEFORMATEX structure.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1.70"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:4.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.8</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.6</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1.70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0004</vuln:cve-id>
    <vuln:published-datetime>2009-01-21T15:30:00.297-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:44.657-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-22T09:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6211" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6211" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" xml:lang="en">TA09-022A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3403" xml:lang="en">http://support.apple.com/kb/HT3403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" xml:lang="en">APPLE-SA-2009-01-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48157" xml:lang="en">quicktime-mpeg2-bo(48157)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0212" xml:lang="en">ADV-2009-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33632" xml:lang="en">33632</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6211" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6211" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted MP3 audio file.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1.70"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:4.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.8</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.6</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1.70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0005</vuln:cve-id>
    <vuln:published-datetime>2009-01-21T15:30:00.327-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:44.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-22T10:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6187" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6187" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" xml:lang="en">TA09-022A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" xml:lang="en">APPLE-SA-2009-01-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48158" xml:lang="en">quicktime-h263-movie-code-execution(48158)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0212" xml:lang="en">ADV-2009-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33386" xml:lang="en">33386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3403" xml:lang="en">http://support.apple.com/kb/HT3403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33632" xml:lang="en">33632</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6187" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6187" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted H.263 encoded movie file that triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1.70"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:6.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.6</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:3.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1.70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0006</vuln:cve-id>
    <vuln:published-datetime>2009-01-21T15:30:00.343-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-02-29T17:42:24.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-22T10:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6153" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6153" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" xml:lang="en">TA09-022A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" xml:lang="en">APPLE-SA-2009-01-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-09-007/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-09-007/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0212" xml:lang="en">ADV-2009-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33388" xml:lang="en">33388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/500391/100/0/threaded" xml:lang="en">20090124 Re: ZDI-09-007: Apple QuickTime Cinepak Codec MDAT Heap Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3403" xml:lang="en">http://support.apple.com/kb/HT3403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33632" xml:lang="en">33632</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51529" xml:lang="en">51529</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2009-01/0215.html" xml:lang="en">20090121 ZDI-09-007: Apple QuickTime Cinepak Codec MDAT Heap Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6153" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6153" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cinepak encoded movie file with a crafted MDAT atom that triggers a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.3.1.70"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:6.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.5.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.6</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:3.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.3.1.70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0007</vuln:cve-id>
    <vuln:published-datetime>2009-01-21T15:30:00.377-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-02-29T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-22T10:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6132" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6132" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" xml:lang="en">TA09-022A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" xml:lang="en">APPLE-SA-2009-01-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-09-008/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-09-008/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0212" xml:lang="en">ADV-2009-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33390" xml:lang="en">33390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3403" xml:lang="en">http://support.apple.com/kb/HT3403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33632" xml:lang="en">33632</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51530" xml:lang="en">51530</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6132" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6132" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime_mpeg-2_playback_component"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime_mpeg-2_playback_component</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0008</vuln:cve-id>
    <vuln:published-datetime>2009-01-22T13:30:03.797-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:45.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-22T13:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5974" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5974" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48162" xml:lang="en">quicktime-mpeg2playback-code-execution(48162)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0211" xml:lang="en">ADV-2009-0211</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021621" xml:lang="en">1021621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33393" xml:lang="en">33393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3404" xml:lang="en">http://support.apple.com/kb/HT3404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33642" xml:lang="en">33642</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce//2009/Jan/msg00001.html" xml:lang="en">APPLE-SA-2009-01-21</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5974" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5974" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted MPEG-2 movie.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0009</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:00.187-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:45.110-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T09:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48713" xml:lang="en">macosx-pixlet-codec-code-execution(48713)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/alerts/2009/Feb/1021718.html" xml:lang="en">1021718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51980" xml:lang="en">51980</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Pixlet codec in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted movie file that triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0010</vuln:cve-id>
    <vuln:published-datetime>2009-05-13T11:30:00.233-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-06-04T01:24:11.703-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-05-14T08:27:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" xml:lang="en">TA09-133A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3549" xml:lang="en">http://support.apple.com/kb/HT3549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" xml:lang="en">APPLE-SA-2009-05-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-09-021/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-09-021/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-09-021" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-09-021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.vupen.com/exploits/Apple_QuickTime_PICT_Poly_Tag_Parsing_Heap_Overflow_PoC_Exploit_1407144.php" xml:lang="en">http://www.vupen.com/exploits/Apple_QuickTime_PICT_Poly_Tag_Parsing_Heap_Overflow_PoC_Exploit_1407144.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1407" xml:lang="en">ADV-2009-1407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1297" xml:lang="en">ADV-2009-1297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022209" xml:lang="en">1022209</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34938" xml:lang="en">34938</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34926" xml:lang="en">34926</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/503878/100/0/threaded" xml:lang="en">20090527 ZDI-09-021: Apple QuickTime PICT Unspecified Tag Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3591" xml:lang="en">http://support.apple.com/kb/HT3591</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35091" xml:lang="en">35091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35074" xml:lang="en">35074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" xml:lang="en">APPLE-SA-2009-06-01-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, and Apple QuickTime before 7.6.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a crafted 0x77 Poly tag and a crafted length field, which triggers a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0011</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:04.827-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:45.313-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T09:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48715" xml:lang="en">macosx-certificate-asst-file-overwrite(48715)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/alerts/2009/Feb/1021720.html" xml:lang="en">1021720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51979" xml:lang="en">51979</vuln:reference>
    </vuln:references>
    <vuln:summary>Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via unknown vectors related to an "insecure file operation" on a temporary file.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0012</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:04.843-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T10:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33809" xml:lang="en">33809</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51977" xml:lang="en">51977</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in CoreText in Apple Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via a crafted Unicode string.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0013</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:04.860-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:45.500-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T09:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48717" xml:lang="en">macosx-dstools-information-disclosure(48717)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33815" xml:lang="en">33815</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/alerts/2009/Feb/1021722.html" xml:lang="en">1021722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:summary>dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as command line arguments, which allows local users to gain privileges by listing process information.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0014</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:04.877-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:45.610-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T09:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33820" xml:lang="en">33820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:summary>Folder Manager in Apple Mac OS X 10.5.6 uses insecure default permissions when recreating a Downloads folder after it has been deleted, which allows local users to bypass intended access restrictions and read the Downloads folder.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0015</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:04.907-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:45.720-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T10:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33821" xml:lang="en">33821</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows local users to obtain sensitive information (filesystem activities and directory names) via unknown vectors related to "credential management."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:1.0::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:1.1.1::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:1.1.2::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0.1::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0.2::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0.3::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0.4::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:3.0.1::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:3.0::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.72::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1.30::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4.2::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7::windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0::windows"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:7.1.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:3.0::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.4.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.4:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1.30::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.72::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:1.1.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.4::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:3.0.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:1.1.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:1.0::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0.3::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0.4::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0:-:windows</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0016</vuln:cve-id>
    <vuln:published-datetime>2009-03-14T14:30:00.420-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:33.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-03-15T08:54:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6001" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6001" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3487" xml:lang="en">http://support.apple.com/kb/HT3487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce//2009/Mar/msg00001.html" xml:lang="en">APPLE-SA-2009-03-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/49200" xml:lang="en">itunes-daap-dos(49200)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0702" xml:lang="en">ADV-2009-0702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34094" xml:lang="en">34094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/501758/100/0/threaded" xml:lang="en">20090313 Apple iTunes DAAP Messages Handling Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.fortiguardcenter.com/advisory/FGA-2009-11.html" xml:lang="en">http://www.fortiguardcenter.com/advisory/FGA-2009-11.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1021842" xml:lang="en">1021842</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34254" xml:lang="en">34254</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/52578" xml:lang="en">52578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0236.html" xml:lang="en">20090312 Apple iTunes DAAP Messages Handling Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6001" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6001" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) message with a crafted Content-Length header.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0017</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:04.920-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:45.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T10:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33811" xml:lang="en">33811</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:summary>csregprinter in the Printing component in Apple Mac OS X 10.4.11 and 10.5.6 does not properly handle error conditions, which allows local users to execute arbitrary code via unknown vectors that trigger a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0018</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:04.937-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:46.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T10:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33816" xml:lang="en">33816</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:summary>The Remote Apple Events server in Apple Mac OS X 10.4.11 and 10.5.6 does not properly initialize a buffer, which allows remote attackers to read portions of memory.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0019">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0019</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:04.953-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:46.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T10:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33814" xml:lang="en">33814</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:summary>Remote Apple Events in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) or obtain sensitive information via unspecified vectors that trigger an out-of-bounds memory access.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0020</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:04.967-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:46.203-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T10:16:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted resource fork that triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ntp:ntp:4.2.4p4"/>
        <cpe-lang:fact-ref name="cpe:/a:ntp:ntp:4.2.4p3"/>
        <cpe-lang:fact-ref name="cpe:/a:ntp:ntp:4.2.4p2"/>
        <cpe-lang:fact-ref name="cpe:/a:ntp:ntp:4.2.4p1"/>
        <cpe-lang:fact-ref name="cpe:/a:ntp:ntp:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ntp:ntp:4.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ntp:ntp:4.2.0</vuln:product>
      <vuln:product>cpe:/a:ntp:ntp:4.2.4p3</vuln:product>
      <vuln:product>cpe:/a:ntp:ntp:4.2.4p4</vuln:product>
      <vuln:product>cpe:/a:ntp:ntp:4.2.2</vuln:product>
      <vuln:product>cpe:/a:ntp:ntp:4.2.4p1</vuln:product>
      <vuln:product>cpe:/a:ntp:ntp:4.2.4p2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0021</vuln:cve-id>
    <vuln:published-datetime>2009-01-07T12:30:00.360-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T23:13:02.653-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-07T14:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10035" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10035" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" xml:lang="en">TA09-133A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.ntp.org/pipermail/announce/2009-January/000055.html" xml:lang="en">[announce] 20090108 NTP 4.2.4p6 Released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1297" xml:lang="en">ADV-2009-1297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0042" xml:lang="en">ADV-2009-0042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021533" xml:lang="en">1021533</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" xml:lang="en">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0046.html" xml:lang="en">RHSA-2009:0046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ocert.org/advisories/ocert-2008-016.html" xml:lang="en">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3549" xml:lang="en">http://support.apple.com/kb/HT3549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.531177" xml:lang="en">SSA:2009-014-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35074" xml:lang="en">35074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34642" xml:lang="en">34642</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33648" xml:lang="en">33648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33558" xml:lang="en">33558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33406" xml:lang="en">33406</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" xml:lang="en">SUSE-SR:2009:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" xml:lang="en">SUSE-SR:2009:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" xml:lang="en">APPLE-SA-2009-05-12</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10035" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10035" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:3.2.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0022</vuln:cve-id>
    <vuln:published-datetime>2009-01-05T15:30:02.390-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:46.423-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-06T10:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00309.html" xml:lang="en">FEDORA-2009-0268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/47733" xml:lang="en">samba-file-system-security-bypass(47733)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0017" xml:lang="en">ADV-2009-0017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntulinux.org/support/documentation/usn/usn-702-1" xml:lang="en">USN-702-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021513" xml:lang="en">1021513</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33118" xml:lang="en">33118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.samba.org/samba/security/CVE-2009-0022.html" xml:lang="en">http://www.samba.org/samba/security/CVE-2009-0022.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:042" xml:lang="en">MDVSA-2009:042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33431" xml:lang="en">33431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33392" xml:lang="en">33392</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33379" xml:lang="en">33379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51152" xml:lang="en">51152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://master.samba.org/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch" xml:lang="en">http://master.samba.org/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch</vuln:reference>
    </vuln:references>
    <vuln:summary>Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection request that specifies a blank share name.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:apr-util:1.3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:apr-util:1.1.0</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.2.2</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:0.9.2</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:0.9.4</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.1.2</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:0.9.1</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.3.0</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.2.8</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.0.1</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.3.4</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.2.6</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.3.1</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.3.3</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.0</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.2.7</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:0.9.3</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.2.1</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:0.9.5</vuln:product>
      <vuln:product>cpe:/a:apache:apr-util:1.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0023</vuln:cve-id>
    <vuln:published-datetime>2009-06-07T21:00:00.530-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-17T23:04:08.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-06-08T12:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12321" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12321" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10968" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10968" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=503928" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=503928</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1812" xml:lang="en">DSA-1812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.html" xml:lang="en">FEDORA-2009-5969</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.html" xml:lang="en">FEDORA-2009-6261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html" xml:lang="en">FEDORA-2009-6014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/50964" xml:lang="en">apache-aprstrmatchprecompile-dos(50964)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/3184" xml:lang="en">ADV-2009-3184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1907" xml:lang="en">ADV-2009-1907</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-787-1" xml:lang="en">USN-787-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-786-1" xml:lang="en">USN-786-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/35221" xml:lang="en">35221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/507855/100/0/threaded" xml:lang="en">20091112 rPSA-2009-0144-1 apr-util</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-1108.html" xml:lang="en">RHSA-2009:1108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-1107.html" xml:lang="en">RHSA-2009:1107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:131" xml:lang="en">MDVSA-2009:131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3" xml:lang="en">http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" xml:lang="en">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478" xml:lang="en">PK99478</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241" xml:lang="en">PK91241</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341" xml:lang="en">PK88341</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2009-0144" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2009-0144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.apache.org/viewvc?view=rev&amp;revision=779880" xml:lang="en">http://svn.apache.org/viewvc?view=rev&amp;revision=779880</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3937" xml:lang="en">http://support.apple.com/kb/HT3937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.538210" xml:lang="en">SSA:2009-167-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200907-03.xml" xml:lang="en">GLSA-200907-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/37221" xml:lang="en">37221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35843" xml:lang="en">35843</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35797" xml:lang="en">35797</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35710" xml:lang="en">35710</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35565" xml:lang="en">35565</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35487" xml:lang="en">35487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35444" xml:lang="en">35444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35395" xml:lang="en">35395</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35360" xml:lang="en">35360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35284" xml:lang="en">35284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34724" xml:lang="en">34724</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=129190899612998&amp;w=2" xml:lang="en">HPSBUX02612</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=129190899612998&amp;w=2" xml:lang="en">HPSBUX02612</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" xml:lang="en">APPLE-SA-2009-11-09-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12321" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12321" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10968" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10968" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.49"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.48"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.47"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.46"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.45"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.61"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.62"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.52"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.51"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.50"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.60"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.59"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.58"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.57"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.56"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.55"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.54"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.53"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.52</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.47</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.53</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.61</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.62</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.46</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.50</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.54</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.42</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.56</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.55</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.44</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.59</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.51</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.57</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.58</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.45</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.49</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.43</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.48</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.60</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0024</vuln:cve-id>
    <vuln:published-datetime>2009-01-13T12:00:01.170-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-13T14:16:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33211" xml:lang="en">33211</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2009/01/12/1" xml:lang="en">[oss-security] 20090112 CVE-2009-0024 kernel: local privilege escalation in sys_remap_file_pages</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.24.y.git;a=commit;h=8a459e44ad837018ea5c34a9efe8eb4ad27ded26" xml:lang="en">http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.24.y.git;a=commit;h=8a459e44ad837018ea5c34a9efe8eb4ad27ded26</vuln:reference>
    </vuln:references>
    <vuln:summary>The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denial of service or gain privileges via unspecified vectors, related to the vm_file structure member, and the mmap_region and do_munmap functions.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isc:bind"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.5:p1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.5-p2-w1:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2:p1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.3_t9b"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.3_t1a"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.2.2:p7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.2:p3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0b1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0b2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0b3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0b4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:bind:9.2.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.2:p4</vuln:product>
      <vuln:product>cpe:/a:isc:bind</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.7</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.2:p7</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.3_t9b</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0a3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.2:p3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9.8</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.4.5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0b4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9.5:p1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.2:p3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0b1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.7</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.5-p2-w1:windows</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9.10</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.4.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9.9</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.3_t1a</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0a5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.1.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2:p1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.4.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.2:p6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.2:p5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0a6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0b3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.9</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.4.7</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0a4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.1.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0a1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0a2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0b2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.3.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9.5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.2:p1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9.6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.2:p2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9.7</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0025</vuln:cve-id>
    <vuln:published-datetime>2009-01-07T12:30:00.390-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T23:13:04.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-07T14:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5569" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5569" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10879" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10879" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" xml:lang="en">TA09-133A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00393.html" xml:lang="en">FEDORA-2009-0350</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.isc.org/software/bind/advisories/cve-2009-0025" xml:lang="en">https://www.isc.org/software/bind/advisories/cve-2009-0025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-2938" xml:lang="en">https://issues.rpath.com/browse/RPL-2938</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1297" xml:lang="en">ADV-2009-1297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0904" xml:lang="en">ADV-2009-0904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0366" xml:lang="en">ADV-2009-0366</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0043" xml:lang="en">ADV-2009-0043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2009-0004.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2009-0004.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33151" xml:lang="en">33151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/502322/100/0/threaded" xml:lang="en">20090401 VMSA-2009-0004 ESX Service Console updates for openssl, bind, and vim</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/500207/100/0/threaded" xml:lang="en">20090120 rPSA-2009-0009-1 bind bind-utils</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" xml:lang="en">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata44.html#008_bind" xml:lang="en">http://www.openbsd.org/errata44.html#008_bind</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ocert.org/advisories/ocert-2008-016.html" xml:lang="en">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2009-0009" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2009-0009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2009-045.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2009-045.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3549" xml:lang="en">http://support.apple.com/kb/HT3549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-250846-1" xml:lang="en">250846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.540362" xml:lang="en">SSA:2009-014-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://security.freebsd.org/advisories/FreeBSD-SA-09:04.bind.asc" xml:lang="en">FreeBSD-SA-09:04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35074" xml:lang="en">35074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33882" xml:lang="en">33882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33683" xml:lang="en">33683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33559" xml:lang="en">33559</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33551" xml:lang="en">33551</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33546" xml:lang="en">33546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33494" xml:lang="en">33494</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" xml:lang="en">APPLE-SA-2009-05-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33" xml:lang="en">http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10879" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10879" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5569" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5569" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:jackrabbit:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:jackrabbit:1.5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:jackrabbit:1.4</vuln:product>
      <vuln:product>cpe:/a:apache:jackrabbit:1.5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0026</vuln:cve-id>
    <vuln:published-datetime>2009-01-21T15:30:00.390-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:46.893-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-22T10:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.apache.org/jira/browse/JCR-1925" xml:lang="en">https://issues.apache.org/jira/browse/JCR-1925</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48110" xml:lang="en">jackrabbit-search-swr-xss(48110)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0177" xml:lang="en">ADV-2009-0177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33360" xml:lang="en">33360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/500196/100/0/threaded" xml:lang="en">20090120 [ANNOUNCE] Apache Jackrabbit 1.5.2 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.apache.org/dist/jackrabbit/RELEASE-NOTES-1.5.2.txt" xml:lang="en">http://www.apache.org/dist/jackrabbit/RELEASE-NOTES-1.5.2.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4942" xml:lang="en">4942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33576" xml:lang="en">33576</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0:cp03"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0:cp04"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0:cp02"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0:cp01"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp01"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp02"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp03"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp04"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0:cp05"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0:cp06"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0:cp05</vuln:product>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0:cp06</vuln:product>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp01</vuln:product>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0:cp02</vuln:product>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp02</vuln:product>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp04</vuln:product>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp03</vuln:product>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0:cp01</vuln:product>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0:cp03</vuln:product>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0:cp04</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0027</vuln:cve-id>
    <vuln:published-datetime>2009-03-09T17:30:00.170-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-21T01:53:33.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-03-10T11:04:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2009-0349.html" xml:lang="en">RHSA-2009:0349</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2009-0347.html" xml:lang="en">RHSA-2009:0347</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2009-0346.html" xml:lang="en">RHSA-2009:0346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://jira.jboss.org/jira/browse/JBPAPP-1548" xml:lang="en">https://jira.jboss.org/jira/browse/JBPAPP-1548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=479668" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=479668</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021817" xml:lang="en">1021817</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34023" xml:lang="en">34023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34112" xml:lang="en">34112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2009-0348.html" xml:lang="en">RHSA-2009:0348</vuln:reference>
    </vuln:references>
    <vuln:summary>The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.49"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.48"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.47"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.46"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.45"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.52"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.51"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.50"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.58"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.57"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.56"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.55"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.54"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.53"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.61"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.62"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.60"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.59"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.12::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.11::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.10::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.2::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.7::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.6::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.5::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.4::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.3::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.9::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.8::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27:rc9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27:rc8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.28"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.52</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.5::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.6::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.47</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.2::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.53</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.61</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.62</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.11::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.46</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.50</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.4::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.54</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.1::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.42</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.56</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.55</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.9::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.3::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.44</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.7::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.59</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.10::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.51</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27:rc9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.8::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.57</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.58</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.12::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.45</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.49</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27:rc8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.43</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.48</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.60</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0028</vuln:cve-id>
    <vuln:published-datetime>2009-02-27T12:30:09.860-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-03-02T10:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7947" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7947" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11187" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11187" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=479932" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=479932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/3316" xml:lang="en">ADV-2009-3316</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-751-1" xml:lang="en">USN-751-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33906" xml:lang="en">33906</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" xml:lang="en">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/503610/100/0/threaded" xml:lang="en">20090516 rPSA-2009-0084-1 kernel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0451.html" xml:lang="en">RHSA-2009:0451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0326.html" xml:lang="en">RHSA-2009:0326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:118" xml:lang="en">MDVSA-2009:118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1800" xml:lang="en">DSA-1800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1794" xml:lang="en">DSA-1794</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1787" xml:lang="en">DSA-1787</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2009-0084" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2009-0084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/37471" xml:lang="en">37471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35394" xml:lang="en">35394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35390" xml:lang="en">35390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35121" xml:lang="en">35121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35120" xml:lang="en">35120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35011" xml:lang="en">35011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34981" xml:lang="en">34981</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34962" xml:lang="en">34962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34917" xml:lang="en">34917</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34680" xml:lang="en">34680</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34033" xml:lang="en">34033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33758" xml:lang="en">33758</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://scarybeastsecurity.blogspot.com/2009/02/linux-kernel-minor-signal-vulnerability.html" xml:lang="en">http://scarybeastsecurity.blogspot.com/2009/02/linux-kernel-minor-signal-vulnerability.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://scary.beasts.org/security/CESA-2009-002.html" xml:lang="en">http://scary.beasts.org/security/CESA-2009-002.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2009-0459.html" xml:lang="en">RHSA-2009:0459</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/52204" xml:lang="en">52204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" xml:lang="en">SUSE-SA:2009:031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" xml:lang="en">SUSE-SA:2009:030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" xml:lang="en">SUSE-SA:2009:010</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7947" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7947" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11187" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11187" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new process exit.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.12::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.11::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.8::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.7::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.6::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.5::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.4::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.3::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.2::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.10::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.9::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.28"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.5::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.6::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.9::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.3::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.7::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.2::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.10::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.8::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.11::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.12::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.4::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.1::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0029</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.467-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-15T16:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01045.html" xml:lang="en">FEDORA-2009-0816</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=479969" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=479969</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33275" xml:lang="en">33275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135" xml:lang="en">MDVSA-2009:135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1794" xml:lang="en">DSA-1794</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1787" xml:lang="en">DSA-1787</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1749" xml:lang="en">DSA-1749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35011" xml:lang="en">35011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34981" xml:lang="en">34981</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34394" xml:lang="en">34394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33674" xml:lang="en">33674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33477" xml:lang="en">33477</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=linux-kernel&amp;m=123155111608910&amp;w=2" xml:lang="en">[linux-kernel] 20090110 Re: [PATCH -v7][RFC]: mutex: implement adaptive spinning</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" xml:lang="en">SUSE-SA:2009:010</vuln:reference>
    </vuln:references>
    <vuln:summary>The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, sparc64, and mips 64-bit platforms requires that a 32-bit argument in a 64-bit register was properly sign extended when sent from a user-mode application, but cannot verify this, which allows local users to cause a denial of service (crash) or possibly gain privileges via a crafted system call.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0030</vuln:cve-id>
    <vuln:published-datetime>2009-01-21T15:30:00.407-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:35.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-22T10:17:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10366" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10366" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2009-0057.html" xml:lang="en">RHSA-2009:0057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=480488" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=480488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=480224" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=480224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48115" xml:lang="en">squirrelmail-sessionid-session-hijacking(48115)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33354" xml:lang="en">33354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1021611" xml:lang="en">1021611</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33611" xml:lang="en">33611</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" xml:lang="en">SUSE-SR:2009:004</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10366" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10366" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.12::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.11::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.8::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.7::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.6::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.5::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.4::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.3::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.2::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.10::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.9::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.28.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.5::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.6::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.9::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.3::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.7::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.28.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.2::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.10::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.8::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.11::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.12::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.4::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.1::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0031</vuln:cve-id>
    <vuln:published-datetime>2009-01-20T21:30:00.313-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-21T12:09:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11386" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11386" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-751-1" xml:lang="en">USN-751-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0360.html" xml:lang="en">RHSA-2009:0360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0331.html" xml:lang="en">RHSA-2009:0331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2009/01/19/4" xml:lang="en">[oss-security] 20090119 CVE-2009-0031 kernel: local denial of service in keyctl_join_session_keyring</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1794" xml:lang="en">DSA-1794</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1787" xml:lang="en">DSA-1787</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1749" xml:lang="en">DSA-1749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35011" xml:lang="en">35011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34981" xml:lang="en">34981</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34762" xml:lang="en">34762</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34502" xml:lang="en">34502</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34394" xml:lang="en">34394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34252" xml:lang="en">34252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33858" xml:lang="en">33858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2009-0264.html" xml:lang="en">RHSA-2009:0264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51501" xml:lang="en">51501</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" xml:lang="en">SUSE-SA:2009:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git2.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0d54ee1c7850a954026deec4cd4885f331da35cc" xml:lang="en">http://git2.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0d54ee1c7850a954026deec4cd4885f331da35cc</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11386" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11386" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Memory leak in the keyctl_join_session_keyring function (security/keys/keyctl.c) in Linux kernel 2.6.29-rc2 and earlier allows local users to cause a denial of service (kernel memory consumption) via unknown vectors related to a "missing kfree."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0032">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:cups"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:mandriva:linux:2008.0"/>
          <cpe-lang:fact-ref name="cpe:/o:mandriva:linux:2008.0::x86_64"/>
          <cpe-lang:fact-ref name="cpe:/o:mandriva:linux:2008.1"/>
          <cpe-lang:fact-ref name="cpe:/o:mandriva:linux:2008.1::x86_64"/>
          <cpe-lang:fact-ref name="cpe:/o:mandriva:linux:2009.0"/>
          <cpe-lang:fact-ref name="cpe:/o:mandriva:corporate_server:3.0"/>
          <cpe-lang:fact-ref name="cpe:/o:mandriva:corporate_server:3.0::x86_64"/>
          <cpe-lang:fact-ref name="cpe:/o:mandriva:corporate_server:4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:mandriva:corporate_server:4.0::x86_64"/>
          <cpe-lang:fact-ref name="cpe:/o:mandriva:multi_network_firewall:2.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:cups</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0032</vuln:cve-id>
    <vuln:published-datetime>2009-01-27T15:30:00.377-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-28T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-28T08:33:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-59"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48210" xml:lang="en">cups-pdflog-symlink(48210)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33418" xml:lang="en">33418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:029" xml:lang="en">MDVSA-2009:029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:028" xml:lang="en">MDVSA-2009:028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:027" xml:lang="en">MDVSA-2009:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1021637" xml:lang="en">1021637</vuln:reference>
    </vuln:references>
    <vuln:summary>CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.23"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.24"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.25"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.26"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.27"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.29"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.3:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.30"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.31"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.33"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.34"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.9:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.20"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.21"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.22"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.23"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.24"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.25"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.26"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.27"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:4.1.10</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.18</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.11</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.18</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.14</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.13</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.24</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.24</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.15</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.16</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.9</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.16</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.29</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.10</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.12</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.39</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.27</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.31</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.11</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.16</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.25</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.7</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.11</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.20</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.14</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.33</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.35</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.22</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.15</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.26</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.7</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.17</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.21</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.6</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.9</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.26</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.9:beta</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.22</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.5</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.8</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.34</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.38</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.12</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.30</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.6</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.7</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.19</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.10</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.21</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.27</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.19</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.12</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.15</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.6</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.13</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.13</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.8</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.37</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.23</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.14</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.5</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.8</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.28</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.20</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.32</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.23</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.9</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.3:beta</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.17</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.36</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.1.25</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0033</vuln:cve-id>
    <vuln:published-datetime>2009-06-05T12:00:00.187-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-04T22:56:24.707-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-06-08T08:04:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5739" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5739" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10231" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10231" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1496" xml:lang="en">ADV-2009-1496</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/35193" xml:lang="en">35193</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/security-6.html" xml:lang="en">http://tomcat.apache.org/security-6.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/security-5.html" xml:lang="en">http://tomcat.apache.org/security-5.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/security-4.html" xml:lang="en">http://tomcat.apache.org/security-4.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.apache.org/viewvc?rev=781362&amp;view=rev" xml:lang="en">http://svn.apache.org/viewvc?rev=781362&amp;view=rev</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.apache.org/viewvc?rev=742915&amp;view=rev" xml:lang="en">http://svn.apache.org/viewvc?rev=742915&amp;view=rev</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01246.html" xml:lang="en">FEDORA-2009-11356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01216.html" xml:lang="en">FEDORA-2009-11352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01156.html" xml:lang="en">FEDORA-2009-11374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/50928" xml:lang="en">tomcat-ajp-dos(50928)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/3056" xml:lang="en">ADV-2010-3056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/3316" xml:lang="en">ADV-2009-3316</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1856" xml:lang="en">ADV-2009-1856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" xml:lang="en">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/504044/100/0/threaded" xml:lang="en">20090603 [SECURITY] CVE-2009-0033 Apache Tomcat DoS when using Java AJP connector</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:176" xml:lang="en">MDVSA-2010:176</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:138" xml:lang="en">MDVSA-2009:138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:136" xml:lang="en">MDVSA-2009:136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2207" xml:lang="en">DSA-2207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-263529-1" xml:lang="en">263529</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1022331" xml:lang="en">1022331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42368" xml:lang="en">42368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/37460" xml:lang="en">37460</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35788" xml:lang="en">35788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35685" xml:lang="en">35685</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35344" xml:lang="en">35344</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35326" xml:lang="en">35326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=136485229118404&amp;w=2" xml:lang="en">SSRT101146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=136485229118404&amp;w=2" xml:lang="en">HPSBUX02860</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" xml:lang="en">SSRT100203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" xml:lang="en">SSRT100203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" xml:lang="en">SUSE-SR:2009:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN87272440/index.html" xml:lang="en">JVN#87272440</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5739" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5739" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10231" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10231" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9_p17"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9_p18"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9_p19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9_p18</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9_p17</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9_p19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0034</vuln:cve-id>
    <vuln:published-datetime>2009-01-30T14:30:00.280-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:36.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-02T09:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6462" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6462" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10856" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10856" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-2954" xml:lang="en">https://issues.rpath.com/browse/RPL-2954</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.novell.com/show_bug.cgi?id=468923" xml:lang="en">https://bugzilla.novell.com/show_bug.cgi?id=468923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1865" xml:lang="en">ADV-2009-1865</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2009-0009.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2009-0009.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sudo.ws/cgi-bin/cvsweb/sudo/parse.c.diff?r1=1.160.2.21&amp;r2=1.160.2.22&amp;f=h" xml:lang="en">http://www.sudo.ws/cgi-bin/cvsweb/sudo/parse.c.diff?r1=1.160.2.21&amp;r2=1.160.2.22&amp;f=h</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021688" xml:lang="en">1021688</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33517" xml:lang="en">33517</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/504849/100/0/threaded" xml:lang="en">20090711 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/500546/100/0/threaded" xml:lang="en">20090129 rPSA-2009-0021-1 sudo</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0267.html" xml:lang="en">RHSA-2009:0267</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:033" xml:lang="en">MDVSA-2009:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327" xml:lang="en">http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2009-0021" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2009-0021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35766" xml:lang="en">35766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33885" xml:lang="en">33885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33840" xml:lang="en">33840</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33753" xml:lang="en">33753</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51736" xml:lang="en">51736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.vmware.com/pipermail/security-announce/2009/000060.html" xml:lang="en">[Security-announce] 20090710 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10856" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10856" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6462" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6462" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0036">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:libvirt:libvirt:0.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:libvirt:libvirt:0.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0036</vuln:cve-id>
    <vuln:published-datetime>2009-02-11T15:30:00.360-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:36.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-12T10:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10127" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10127" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/libvir-list/2009-January/msg00728.html" xml:lang="en">[libvir-list] 20090128 Re: [libvirt] [PATCH] proxy: Fix use of uninitalized memory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/libvir-list/2009-January/msg00726.html" xml:lang="en">[libvir-list] 20090128 Re: [libvirt] [PATCH] proxy: Fix use of uninitalized memory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/libvir-list/2009-January/msg00699.html" xml:lang="en">[libvir-list] 20090127 [libvirt] [PATCH] proxy: Fix use of uninitalized memory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=484947" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=484947</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33724" xml:lang="en">33724</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0382.html" xml:lang="en">RHSA-2009:0382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34397" xml:lang="en">34397</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2009/02/10/8" xml:lang="en">[oss-security] 20090210 libvirt_proxy heads up</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.et.redhat.com/?p=libvirt.git;a=commitdiff;h=2bb0657e28" xml:lang="en">http://git.et.redhat.com/?p=libvirt.git;a=commitdiff;h=2bb0657e28</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10127" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10127" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privileges by sending a portion of the header of a virProxyPacket packet, and then sending the remainder of the packet with crafted values in the header, related to use of uninitialized memory in a validation check.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0037">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:6.1beta"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:6.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.16.3"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.16.4"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.8"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.9"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.10"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.10.8"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.12"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.12.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.13"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.13.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.14"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.15"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.15.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.15.3"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.17"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.18"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:curl:7.19.3"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.12"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.12.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.12.3"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.13.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.13.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.14"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.15"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.15.1"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.15.3"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.16.3"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.19.3"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.15.2"/>
        <cpe-lang:fact-ref name="cpe:/a:curl:libcurl:7.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:curl:curl:7.7.2</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.10.2</vuln:product>
      <vuln:product>cpe:/a:curl:curl:6.0</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.4</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.5</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.2.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.16.4</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.9.5</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.4.2</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.11.1</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.15</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.1.1</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.13</vuln:product>
      <vuln:product>cpe:/a:curl:curl:6.3.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.19.3</vuln:product>
      <vuln:product>cpe:/a:curl:curl:6.3</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.2</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.9.6</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.7</vuln:product>
      <vuln:product>cpe:/a:curl:curl:6.4</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.9.4</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.9.2</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.10.3</vuln:product>
      <vuln:product>cpe:/a:curl:curl:6.2</vuln:product>
      <vuln:product>cpe:/a:curl:curl:6.1beta</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.13.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:6.5.1</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.14.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.9.8</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.10.1</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.12</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.10.5</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.3</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.6.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.14</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.18</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.7.1</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.15.2</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.6</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.9</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.12</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.7.3</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.19.3</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.12.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.4.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.10.4</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.10.8</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:5.11</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.13.2</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.15</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.14</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.12.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:6.5</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.13.2</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.12.2</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.5.2</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.9.3</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.15.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:6.5.2</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.10.6</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.12.2</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.12.3</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.8</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.15.3</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.16.3</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.8.2</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.9.7</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.10</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.10.7</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.16.3</vuln:product>
      <vuln:product>cpe:/a:curl:curl:5.11</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.17</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.8.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.14.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.15.3</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.5.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.9.1</vuln:product>
      <vuln:product>cpe:/a:curl:libcurl:7.15.1</vuln:product>
      <vuln:product>cpe:/a:curl:curl:7.13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0037</vuln:cve-id>
    <vuln:published-datetime>2009-03-04T21:30:00.250-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:37.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-03-05T10:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6074" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6074" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11054" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11054" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0581" xml:lang="en">ADV-2009-0581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33962" xml:lang="en">33962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://curl.haxx.se/lxr/source/CHANGES" xml:lang="en">http://curl.haxx.se/lxr/source/CHANGES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://curl.haxx.se/docs/adv_20090303.html" xml:lang="en">http://curl.haxx.se/docs/adv_20090303.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/49030" xml:lang="en">curl-location-security-bypass(49030)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.withdk.com/archives/Libcurl_arbitrary_file_access.pdf" xml:lang="en">http://www.withdk.com/archives/Libcurl_arbitrary_file_access.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.withdk.com/2009/03/03/curllibcurl-redirect-arbitrary-file-access/" xml:lang="en">http://www.withdk.com/2009/03/03/curllibcurl-redirect-arbitrary-file-access/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1865" xml:lang="en">ADV-2009-1865</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2009-0009.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2009-0009.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-726-1" xml:lang="en">USN-726-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021783" xml:lang="en">1021783</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/504849/100/0/threaded" xml:lang="en">20090711 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/501757/100/0/threaded" xml:lang="en">20090312 rPSA-2009-0042-1 curl</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0341.html" xml:lang="en">RHSA-2009:0341</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1738" xml:lang="en">DSA-1738</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0042" xml:lang="en">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.476602" xml:lang="en">SSA:2009-069-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200903-21.xml" xml:lang="en">GLSA-200903-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35766" xml:lang="en">35766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34399" xml:lang="en">34399</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34259" xml:lang="en">34259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34255" xml:lang="en">34255</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34251" xml:lang="en">34251</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34237" xml:lang="en">34237</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34202" xml:lang="en">34202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34138" xml:lang="en">34138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.vmware.com/pipermail/security-announce/2009/000060.html" xml:lang="en">[Security-announce] 20090710 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html" xml:lang="en">SUSE-SR:2009:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11054" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11054" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6074" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6074" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:geronimo:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:geronimo:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:geronimo:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:geronimo:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:geronimo:2.1</vuln:product>
      <vuln:product>cpe:/a:apache:geronimo:2.1.2</vuln:product>
      <vuln:product>cpe:/a:apache:geronimo:2.1.3</vuln:product>
      <vuln:product>cpe:/a:apache:geronimo:2.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0038</vuln:cve-id>
    <vuln:published-datetime>2009-04-17T10:30:00.530-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-04-28T01:37:14.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-17T11:26:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://issues.apache.org/jira/browse/GERONIMO-4597" xml:lang="en">http://issues.apache.org/jira/browse/GERONIMO-4597</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214" xml:lang="en">http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1089" xml:lang="en">ADV-2009-1089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34562" xml:lang="en">34562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/502734/100/0/threaded" xml:lang="en">20090416 [DSECRG-09-019] Apache Geronimo - XSS vulnerabilities.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34715" xml:lang="en">34715</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://dsecrg.com/pages/vul/show.php?id=119" xml:lang="en">http://dsecrg.com/pages/vul/show.php?id=119</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring; or (5) the PATH_INFO to the default URI under console/portal/.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:geronimo:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:geronimo:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:geronimo:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:geronimo:2.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:geronimo:2.1.2</vuln:product>
      <vuln:product>cpe:/a:apache:geronimo:2.1</vuln:product>
      <vuln:product>cpe:/a:apache:geronimo:2.1.3</vuln:product>
      <vuln:product>cpe:/a:apache:geronimo:2.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0039</vuln:cve-id>
    <vuln:published-datetime>2009-04-17T10:30:00.547-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-04-28T01:37:15.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-17T11:25:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1089" xml:lang="en">ADV-2009-1089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34562" xml:lang="en">34562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/502735/100/0/threaded" xml:lang="en">20090416 [DSECRG-09-020] Apache Geronimo - XSRF vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34715" xml:lang="en">34715</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://issues.apache.org/jira/browse/GERONIMO-4597" xml:lang="en">http://issues.apache.org/jira/browse/GERONIMO-4597</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214" xml:lang="en">http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://dsecrg.com/pages/vul/show.php?id=120" xml:lang="en">http://dsecrg.com/pages/vul/show.php?id=120</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.28:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.29:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.29:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.29:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.29:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.34"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.33"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.31"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.30"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.28:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.28:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.28:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.28:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.27:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.27:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.27:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.27:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.27:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.25:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.25:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.24:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.23:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.23:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.25"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.27:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.23:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.23:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.22:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.23:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.21:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.21:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.19:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.19:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.19:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.19:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.15:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.15:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.15:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.17:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.12:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.12:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.11:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.11:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.11:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.11:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.10:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.10:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9:beta9"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9:beta10"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.9:beta8"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.8:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.8:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.8:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.8:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.8:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.7:beta12"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.7:beta11"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.7:beta14"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.7:beta13"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.7:beta16"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.7:beta15"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.7:beta18"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.7:beta17"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.6:h"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.6:g"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.6:j"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.6:i"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.6:a"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.6:d"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.6:e"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.6:f"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:0.95"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:0.89c"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.26:beta01"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.25:rc02"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.25:rc01"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.25:beta06"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.26:beta03"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.26:beta02"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.25:beta05"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.25:beta04"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.25:beta03"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.26"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.29"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.28"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.26:beta05"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.26:beta04"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.26:beta06"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.26:rc01"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.27"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.33"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.34"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.32"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.31"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.30"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.25"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.24"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.23"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.22:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.22:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.22:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.22:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.22:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.22"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.21:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.21:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.21:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.21:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.21:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.21"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.20:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.20:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.20:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.20:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.20:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.20:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.13:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.11:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.11:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.11:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.11:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.13"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.11:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.13:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.11:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.11:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta8"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta9"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.20"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.18"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta33"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta31"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta32"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta29"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta30"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta28"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta23"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta24"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta21"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta22"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta19"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta20"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta27"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta25"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta26"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta17"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta18"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta10"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta12"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta11"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta14"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta13"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta16"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.19:beta15"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.16:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.17:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.17:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.17:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.17:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.17:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.17:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.16:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.16:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.15:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.15:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.15:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.15:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.15:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.15:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.15:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.14:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.14:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.13:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.15:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.15:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.15:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.14:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.15:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.10:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.10:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.10:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.10:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.10:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.11:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.10:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.10:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.10:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.1:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.1:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.1:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.1:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.10:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.10:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.9:beta9"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.9:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.9:beta10"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.9:beta8"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.9:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.9:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.9:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.9:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.9:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.9:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.9:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.8:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.8:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.8:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.8:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.8:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.8:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.8:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.8:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.8:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.8:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.7:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.7:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.6:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.6:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.6:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.6:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.6:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.6:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.6:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.6:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.5:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.5:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.4:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.4:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.4:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.3:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.3:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.3:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.2:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.2:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.2:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.2:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.2:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.2:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:libpng:libpng:1.2.2:rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:libpng:libpng:1.2.0:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta16</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.22:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta31</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.6:rc5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta14</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.7</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.27:rc4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.11:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.22:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.7:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.9:beta9</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.13:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta32</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.21:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.12:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.25:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.1:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.19</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.7:beta17</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.42</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.0:beta5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.4:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.23:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.4:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.22</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.3:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.14:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.15:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.21:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.8:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.16</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta29</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.9:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.15:rc5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta17</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.26:rc01</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.12</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.10:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.28:rc5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.25:rc01</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.22</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.28:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.6:j</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.15:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.0:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.8:rc4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.30</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.8:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.25:beta05</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.8:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.18</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.6:d</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.2:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.9:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.27:rc5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta13</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.6:h</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.10:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.18</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.15:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.14:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.20:rc4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.15</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.2:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.26:beta06</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.10:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.26:beta04</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta21</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.15</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:0.89c</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.11:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.23:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.7:beta11</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.11:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta11</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.6:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.8</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.13</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.21:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.15:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.19:rc5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.25:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.26:beta03</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.10</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.11</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.11:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.21:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.6:g</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.8</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.6:a</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta26</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.26</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.10</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.9</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta18</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.33</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.20:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.16:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.22:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.8:rc5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.10:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.5:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta15</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.9:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.16:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.17:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.17:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.7:beta14</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.28</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.26:beta01</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.28:rc6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.3:rc6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.15:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.1:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta30</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.27:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.5:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.25</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.9:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.33</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.27:rc6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.8:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.8:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.3:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.10:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta8</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.2:beta6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.2:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9:beta7</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.11:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.8:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.1:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.7:beta18</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.3:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta20</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.21</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.9:beta5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.19:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.14:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.38</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.6:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.5:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.28:rc4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.27:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.17:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.15:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.15:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.20:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.5:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.29:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.28</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.7:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.1:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.14</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.6:f</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.11:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.7:beta13</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.10:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.6:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.7:beta15</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta9</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.11:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta28</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.25:beta03</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.29</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.17:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.21:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.23</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.31</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.8:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.13:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.0:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.20</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.10:beta5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.5:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.0:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.1:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.8:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.41</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.9:beta8</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.32</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:rc4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.7:beta12</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9:beta8</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.11</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9:beta5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.13</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.6:i</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.1:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.15:beta5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.25</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.27</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.7</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.13:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.21</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.28:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.17:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.11:rc5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.11:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta10</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.4:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:rc5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.19:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta25</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.5:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.27</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.8:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.26:beta05</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.29:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.22:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.9:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.15:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.9:beta6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.23:rc5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.14</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.20:rc5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.9:beta7</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta19</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.17:rc4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.10:beta7</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.21:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.25:rc02</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta7</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.34</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.8:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.4:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.6:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta12</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta24</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.30</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.15:beta6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.2:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.16:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.0</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.24</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.32</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta22</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9:beta9</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta33</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.34</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.35</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.22:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.25:beta06</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.10:beta6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.11:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.37</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.29</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.20</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.26</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.6:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.16</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta27</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.24</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.6:e</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.11:beta4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.10:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.11:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.29:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.9:beta10</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.20:rc3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.6:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.20:rc6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.19:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta23</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.27:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.6:rc4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.15:rc4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.23</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.26:beta02</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.8:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.23:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.31</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.17</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.0</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.10:beta1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.21:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.17</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.25:beta04</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.40</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.23:rc4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.8:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.15:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.17:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:0.95</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.2:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.3:rc4</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9:beta3</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9:beta2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.2:beta5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9:beta10</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.24:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.7:beta16</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.12:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.3:rc5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.15:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.29:rc2</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.9:beta6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.19:rc6</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.6:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.22:rc1</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.8:beta5</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.0.39</vuln:product>
      <vuln:product>cpe:/a:libpng:libpng:1.2.10:rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0040</vuln:cve-id>
    <vuln:published-datetime>2009-02-22T17:30:00.203-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-14T22:53:14.150-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-23T16:03:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6458" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6458" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10316" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10316" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" xml:lang="en">TA09-218A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" xml:lang="en">TA09-133A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/649212" xml:lang="en">VU#649212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" xml:lang="en">FEDORA-2009-2884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" xml:lang="en">FEDORA-2009-2882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00412.html" xml:lang="en">FEDORA-2009-1976</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00272.html" xml:lang="en">FEDORA-2009-2045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48819" xml:lang="en">libpng-pointer-arrays-code-execution(48819)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/2172" xml:lang="en">ADV-2009-2172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1621" xml:lang="en">ADV-2009-1621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1560" xml:lang="en">ADV-2009-1560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1522" xml:lang="en">ADV-2009-1522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1462" xml:lang="en">ADV-2009-1462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1451" xml:lang="en">ADV-2009-1451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1297" xml:lang="en">ADV-2009-1297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0632" xml:lang="en">ADV-2009-0632</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0473" xml:lang="en">ADV-2009-0473</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0469" xml:lang="en">ADV-2009-0469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2009-0007.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2009-0007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33990" xml:lang="en">33990</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33827" xml:lang="en">33827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/505990/100/0/threaded" xml:lang="en">20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/503912/100/0/threaded" xml:lang="en">20090529 VMSA-2009-0007 VMware Hosted products and ESX and ESXi patches resolve security issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/501767/100/0/threaded" xml:lang="en">20090312 rPSA-2009-0046-1 libpng</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0340.html" xml:lang="en">RHSA-2009:0340</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0333.html" xml:lang="en">RHSA-2009:0333</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0325.html" xml:lang="en">RHSA-2009:0325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0315.html" xml:lang="en">RHSA-2009:0315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:083" xml:lang="en">MDVSA-2009:083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:075" xml:lang="en">MDVSA-2009:075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:051" xml:lang="en">MDVSA-2009:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1830" xml:lang="en">DSA-1830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1750" xml:lang="en">DSA-1750</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2009-0046" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2009-0046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document" xml:lang="en">http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3757" xml:lang="en">http://support.apple.com/kb/HT3757</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3639" xml:lang="en">http://support.apple.com/kb/HT3639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3613" xml:lang="en">http://support.apple.com/kb/HT3613</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3549" xml:lang="en">http://support.apple.com/kb/HT3549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020521.1-1" xml:lang="en">1020521</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-259989-1" xml:lang="en">259989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=1689&amp;release_id=662441" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=1689&amp;release_id=662441</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://sourceforge.net/mailarchive/message.php?msg_name=e56ccc8f0902181726i200f4bf0n20d919473ec409b7%40mail.gmail.com" xml:lang="en">[png-mng-implement] 20090219 libpng-1.2.35 and libpng-1.0.43 fix security vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.433952" xml:lang="en">SSA:2009-083-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" xml:lang="en">SSA:2009-083-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-201209-25.xml" xml:lang="en">GLSA-201209-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200903-28.xml" xml:lang="en">GLSA-200903-28</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/36096" xml:lang="en">36096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35386" xml:lang="en">35386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35379" xml:lang="en">35379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35302" xml:lang="en">35302</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35258" xml:lang="en">35258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35074" xml:lang="en">35074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34464" xml:lang="en">34464</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34462" xml:lang="en">34462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34388" xml:lang="en">34388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34324" xml:lang="en">34324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34320" xml:lang="en">34320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34272" xml:lang="en">34272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34265" xml:lang="en">34265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34210" xml:lang="en">34210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34152" xml:lang="en">34152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34145" xml:lang="en">34145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34143" xml:lang="en">34143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34140" xml:lang="en">34140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34137" xml:lang="en">34137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33976" xml:lang="en">33976</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33970" xml:lang="en">33970</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.vmware.com/pipermail/security-announce/2009/000062.html" xml:lang="en">[security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.html" xml:lang="en">SUSE-SA:2009:023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html" xml:lang="en">SUSE-SA:2009:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" xml:lang="en">SUSE-SR:2009:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" xml:lang="en">APPLE-SA-2009-05-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" xml:lang="en">APPLE-SA-2009-06-17-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" xml:lang="en">APPLE-SA-2009-06-08-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" xml:lang="en">APPLE-SA-2009-08-05-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://downloads.sourceforge.net/libpng/libpng-1.2.34-ADVISORY.txt" xml:lang="en">http://downloads.sourceforge.net/libpng/libpng-1.2.34-ADVISORY.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.simplesystems.org/pub/png/src/libpng-1.2.34-ADVISORY.txt" xml:lang="en">ftp://ftp.simplesystems.org/pub/png/src/libpng-1.2.34-ADVISORY.txt</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6458" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6458" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10316" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10316" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0041">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.11:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.10:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.12.1:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.12:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.14:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.13:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.13"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.0beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.21.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.20"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.16:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.15:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.19:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.17:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.20:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.2:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.21.1:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.21:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.18:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.22"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.19"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.21"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.18"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.22:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.26.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.26.2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.28"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.30.3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.30.2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.30"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.27"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.26"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.29"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.24"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.25"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.3:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.23"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.26.2:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.26.1:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.26:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.25:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.24:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.23:netsec"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.2.30.4"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.16"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.18.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.17"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.16.2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.15"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.14"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.13"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.18"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4_revision_95946"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4beta"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.19.2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.20"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.20:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.20:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.20:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.21"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.21:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.21:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.21.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.21.2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.22"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.22:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.22:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.22.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.22.2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.23"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.23:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.23:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.4.23:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta8"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta9"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:open_source:1.6.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:a"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:b.2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:c.1.0:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:asterisk:asterisk_business_edition:c.1.0:beta8"/>
        <cpe-lang:fact-ref name="cpe:/h:asterisk:s800i_appliance:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.8</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.23</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.16:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0.3</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.19:rc3</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0.3:rc1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.25:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.21</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.18.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.21.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.12</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.20:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.21:rc1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.12.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.11</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.22</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.13:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.16.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.3</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.0:beta2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.23:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.3.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.0:beta4</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.17</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.21.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.13</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.5.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.21.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.26.1:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta7</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.10.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.19.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.23:rc3</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0:rc5</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.10</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.22.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.16</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.30</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.20</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.7</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.18</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.26.2:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0:rc4</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.26.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.14</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.0beta1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.10:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.17</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.12</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.30.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.3.6</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.30.4</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.30.3</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.24:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4beta</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.20:rc3</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.18:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.25</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.10</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.9</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.22:rc4</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.13</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.26.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.19:rc1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.15:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.3.5</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta9</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.24</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.1.3.3</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta8</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.15</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.12.1:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.27</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.0:beta2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.19:rc2</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.2.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.20</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.20:rc1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.12:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta5</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.0:beta1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.5.3</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.4</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.3.3</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.5.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:a</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.3:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.0:beta3</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.12.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.28</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.19:rc4</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.19:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.16</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.11:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.18</vuln:product>
      <vuln:product>cpe:/h:asterisk:s800i_appliance:1.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.5</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.23:rc1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.26:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta3</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.11</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.19</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.2.0</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.0</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.23</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.0</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.23:rc2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.22</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.19.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta7.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.3.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.14</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0:rc6</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.29</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.20:rc2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.22:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.3</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.5.0</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.2.3.4</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.15</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4_revision_95946</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.26</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.21</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:b.1.3.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.2:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.17:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.22:rc3</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.7.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.21.1:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.14:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.0beta2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.19</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.6.0:beta4</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.2.21:netsec</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.16.2</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.6</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:c.1.0:beta7</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.22.1</vuln:product>
      <vuln:product>cpe:/a:asterisk:open_source:1.4.21:rc2</vuln:product>
      <vuln:product>cpe:/a:asterisk:asterisk_business_edition:c.1.0:beta8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0041</vuln:cve-id>
    <vuln:published-datetime>2009-01-14T18:30:00.187-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:48.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-15T09:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33174" xml:lang="en">33174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0063" xml:lang="en">ADV-2009-0063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021549" xml:lang="en">1021549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499884/100/0/threaded" xml:lang="en">20090108 AST-2009-001: Information leak in IAX2 authentication</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1952" xml:lang="en">DSA-1952</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4910" xml:lang="en">4910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200905-01.xml" xml:lang="en">GLSA-200905-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/37677" xml:lang="en">37677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34982" xml:lang="en">34982</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33453" xml:lang="en">33453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://downloads.digium.com/pub/security/AST-2009-001.html" xml:lang="en">http://downloads.digium.com/pub/security/AST-2009-001.html</vuln:reference>
    </vuln:references>
    <vuln:summary>IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ca:anti-virus_for_the_enterprise:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:anti-virus_for_the_enterprise:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:anti-virus:2007:8"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:anti-virus:2008"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:internet_security_suite_plus_2008"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:internet_security_suite_2008"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:internet_security_suite_2007:3"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:threat_manager_for_the_enterprise:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:antivirus_gateway:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:secure_content_manager:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:secure_content_manager:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:anti-spyware:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:anti-spyware:2008"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:anti-spyware_for_the_enterprise:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:arcserve_backup:r11.1:_nil_:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:arcserve_backup:r11.5_nil_:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:arcserve_backup:r12.0_nil_:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:arcserve_backup:r11.1:_nil_:linux"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:arcserve_backup:r11.5_nil_:linux"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:arcserve_client_agent:_nil_:_nil_:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_intrusion_detection:2.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_intrusion_detection:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_intrusion_detection:3.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_intrusion_detection:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:common_services:11"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:common_services:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:anti-virus_sdk"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:anti-virus_for_the_enterprise:r8"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_ez_antivirus:r6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_ez_antivirus:r7"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:threat_manager_for_the_enterprise:r8"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:protection_suites:r2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:protection_suites:r3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:protection_suites:r3"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:anti-spyware_for_the_enterprise:r8"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:network_and_systems_management:r11"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:network_and_systems_management:r11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:network_and_systems_management:r3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:network_and_systems_management:r3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:arcserve_client_agent:_nil_:_nil_:windows</vuln:product>
      <vuln:product>cpe:/a:ca:network_and_systems_management:r11.1</vuln:product>
      <vuln:product>cpe:/a:ca:protection_suites:r2</vuln:product>
      <vuln:product>cpe:/a:ca:secure_content_manager:8.1</vuln:product>
      <vuln:product>cpe:/a:ca:common_services:11</vuln:product>
      <vuln:product>cpe:/a:ca:anti-virus:2008</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_ez_antivirus:r6.1</vuln:product>
      <vuln:product>cpe:/a:ca:threat_manager_for_the_enterprise:r8</vuln:product>
      <vuln:product>cpe:/a:ca:secure_content_manager:8.0</vuln:product>
      <vuln:product>cpe:/a:ca:anti-virus:2007:8</vuln:product>
      <vuln:product>cpe:/a:ca:internet_security_suite_plus_2008</vuln:product>
      <vuln:product>cpe:/a:ca:anti-virus_sdk</vuln:product>
      <vuln:product>cpe:/a:ca:common_services:11.1</vuln:product>
      <vuln:product>cpe:/a:ca:anti-spyware:2007</vuln:product>
      <vuln:product>cpe:/a:ca:anti-spyware:2008</vuln:product>
      <vuln:product>cpe:/a:ca:anti-virus_for_the_enterprise:8.1</vuln:product>
      <vuln:product>cpe:/a:ca:anti-spyware_for_the_enterprise:r8</vuln:product>
      <vuln:product>cpe:/a:ca:internet_security_suite_2007:3</vuln:product>
      <vuln:product>cpe:/a:ca:antivirus_gateway:7.1</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_intrusion_detection:2.0:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_intrusion_detection:4.0</vuln:product>
      <vuln:product>cpe:/a:ca:network_and_systems_management:r3.0</vuln:product>
      <vuln:product>cpe:/a:ca:threat_manager_for_the_enterprise:8.1</vuln:product>
      <vuln:product>cpe:/a:ca:network_and_systems_management:r3.1</vuln:product>
      <vuln:product>cpe:/a:ca:arcserve_backup:r11.1:_nil_:linux</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_ez_antivirus:r7</vuln:product>
      <vuln:product>cpe:/a:ca:anti-virus_for_the_enterprise:r8</vuln:product>
      <vuln:product>cpe:/a:ca:protection_suites:r3.1</vuln:product>
      <vuln:product>cpe:/a:ca:anti-virus_for_the_enterprise:7.1</vuln:product>
      <vuln:product>cpe:/a:ca:arcserve_backup:r12.0_nil_:windows</vuln:product>
      <vuln:product>cpe:/a:ca:network_and_systems_management:r11</vuln:product>
      <vuln:product>cpe:/a:ca:protection_suites:r3</vuln:product>
      <vuln:product>cpe:/a:ca:arcserve_backup:r11.1:_nil_:windows</vuln:product>
      <vuln:product>cpe:/a:ca:anti-spyware_for_the_enterprise:8.1</vuln:product>
      <vuln:product>cpe:/a:ca:internet_security_suite_2008</vuln:product>
      <vuln:product>cpe:/a:ca:arcserve_backup:r11.5_nil_:linux</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_intrusion_detection:3.0:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:arcserve_backup:r11.5_nil_:windows</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_intrusion_detection:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0042</vuln:cve-id>
    <vuln:published-datetime>2009-01-27T20:30:00.453-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:48.953-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-28T11:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48261" xml:lang="en">ca-antivirus-engine-security-bypass(48261)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0270" xml:lang="en">ADV-2009-0270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021639" xml:lang="en">1021639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33464" xml:lang="en">33464</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/500417/100/0/threaded" xml:lang="en">20090127 CA20090126-01: CA Anti-Virus Engine Detection Evasion Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197601" xml:lang="en">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197601</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/26/ca20090126-01-ca-anti-virus-engine-detection-evasion-multiple-vulnerabilities.aspx" xml:lang="en">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/26/ca20090126-01-ca-anti-virus-engine-detection-evasion-multiple-vulnerabilities.aspx</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA products allow remote attackers to bypass virus detection via a malformed archive file.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ca:service_level_management:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:service_metric_analysis:r11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:service_metric_analysis:r11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:service_metric_analysis:r11.1:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:service_metric_analysis:r11.1</vuln:product>
      <vuln:product>cpe:/a:ca:service_level_management:3.5</vuln:product>
      <vuln:product>cpe:/a:ca:service_metric_analysis:r11.1:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:service_metric_analysis:r11.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0043</vuln:cve-id>
    <vuln:published-datetime>2009-01-08T14:30:11.250-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:49.063-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T08:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=196148" xml:lang="en">https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=196148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33161" xml:lang="en">33161</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0053" xml:lang="en">ADV-2009-0053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499857/100/0/threaded" xml:lang="en">20090107 CA20090107-01: CA Service Metric Analysis and CA Service Level Management smmsnmpd Arbitrary Command Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4887" xml:lang="en">4887</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/07.aspx" xml:lang="en">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/07.aspx</vuln:reference>
    </vuln:references>
    <vuln:summary>The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which allows remote attackers to execute arbitrary commands via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:grid_engine:5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:grid_engine:5.3:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:grid_engine:5.3:beta1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:grid_engine:5.3:beta1</vuln:product>
      <vuln:product>cpe:/a:sun:grid_engine:5.3</vuln:product>
      <vuln:product>cpe:/a:sun:grid_engine:5.3:beta2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0046</vuln:cve-id>
    <vuln:published-datetime>2009-01-07T13:30:01.453-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T23:13:08.560-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-07T15:07:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0045" xml:lang="en">ADV-2009-0045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" xml:lang="en">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ocert.org/advisories/ocert-2008-016.html" xml:lang="en">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.99"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.91"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.91a"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.91b"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.90a"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.90b"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.90c"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.20a"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.19a"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.19b"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.18b"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.18c"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.17a"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.16a"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.15b"/>
        <cpe-lang:fact-ref name="cpe:/a:gale:gale:0.15c"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gale:gale:0.16</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.15b</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.90c</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.19a</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.15c</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.18</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.90a</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.91a</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.18b</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.17a</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.21</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.99</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.90b</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.16a</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.19b</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.17</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.18c</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.91b</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.19</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.91</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.15</vuln:product>
      <vuln:product>cpe:/a:gale:gale:0.20a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0047</vuln:cve-id>
    <vuln:published-datetime>2009-01-07T13:30:13.280-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T23:13:08.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-07T16:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0046" xml:lang="en">ADV-2009-0046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" xml:lang="en">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ocert.org/advisories/ocert-2008-016.html" xml:lang="en">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openevidence:openevidence:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openevidence:openevidence:1.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openevidence:openevidence:1.0.6</vuln:product>
      <vuln:product>cpe:/a:openevidence:openevidence:1.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0048</vuln:cve-id>
    <vuln:published-datetime>2009-01-07T13:30:15.827-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T23:13:08.950-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-07T16:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0047" xml:lang="en">ADV-2009-0047</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" xml:lang="en">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ocert.org/advisories/ocert-2008-016.html" xml:lang="en">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenEvidence 1.0.6 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eid:eidlib:2.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eid:eidlib:2.6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0049</vuln:cve-id>
    <vuln:published-datetime>2009-01-07T13:30:15.843-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T23:13:09.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-07T17:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" xml:lang="en">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ocert.org/advisories/ocert-2008-016.html" xml:lang="en">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34029" xml:lang="en">34029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" xml:lang="en">SUSE-SR:2009:005</vuln:reference>
    </vuln:references>
    <vuln:summary>Belgian eID middleware (eidlib) 2.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:entrouvert:lasso:2.2.1-0"/>
        <cpe-lang:fact-ref name="cpe:/a:entrouvert:lasso:2.0.0-1"/>
        <cpe-lang:fact-ref name="cpe:/a:entrouvert:lasso:1.9.9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:entrouvert:lasso:2.0.0-1</vuln:product>
      <vuln:product>cpe:/a:entrouvert:lasso:1.9.9.0</vuln:product>
      <vuln:product>cpe:/a:entrouvert:lasso:2.2.1-0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0050</vuln:cve-id>
    <vuln:published-datetime>2009-01-07T13:30:15.860-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T23:13:09.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-07T17:07:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/47837" xml:lang="en">openssl-dsa-verify-security-bypass(47837)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" xml:lang="en">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ocert.org/advisories/ocert-2008-016.html" xml:lang="en">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.25"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:zxid:zxid:0.29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zxid:zxid:0.13</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.10</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.4</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.6</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.26</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.12</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.16</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.2</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.9</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.28</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.8</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.11</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.17</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.21</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.1</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.15</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.22</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.25</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.20</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.14</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.7</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.18</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.27</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.5</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.29</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.3</vuln:product>
      <vuln:product>cpe:/a:zxid:zxid:0.19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0051</vuln:cve-id>
    <vuln:published-datetime>2009-01-07T13:30:15.890-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T23:13:09.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-07T17:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/47837" xml:lang="en">openssl-dsa-verify-security-bypass(47837)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" xml:lang="en">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ocert.org/advisories/ocert-2008-016.html" xml:lang="en">http://www.ocert.org/advisories/ocert-2008-016.html</vuln:reference>
    </vuln:references>
    <vuln:summary>ZXID 0.29 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0052">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:netgear:wndap330_firmware:2.1.11"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:atheros:ar9160-bc1a_chipset"/>
          <cpe-lang:fact-ref name="cpe:/h:netgear:wndap330"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:atheros:ar9160-bc1a_chipset</vuln:product>
      <vuln:product>cpe:/a:netgear:wndap330_firmware:2.1.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0052</vuln:cve-id>
    <vuln:published-datetime>2009-11-12T18:30:00.577-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-05T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.5</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-11-13T08:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/54216" xml:lang="en">netgear-wndap330-frame-dos(54216)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/3212" xml:lang="en">ADV-2009-3212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/36991" xml:lang="en">36991</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/507777/100/0/threaded" xml:lang="en">20091110 Atheros Driver Reserved Frame Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/59880" xml:lang="en">59880</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/37344" xml:lang="en">37344</vuln:reference>
    </vuln:references>
    <vuln:summary>The Atheros wireless driver, as used in Netgear WNDAP330 Wi-Fi access point with firmware 2.1.11 and other versions before 3.0.3 on the Atheros AR9160-BC1A chipset, and other products, allows remote authenticated users to cause a denial of service (device reboot or hang) and possibly execute arbitrary code via a truncated reserved management frame.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.5"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.6"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.6</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.5</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0053</vuln:cve-id>
    <vuln:published-datetime>2009-01-16T16:30:03.407-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:49.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-19T15:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0140" xml:lang="en">ADV-2009-0140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33268" xml:lang="en">33268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml" xml:lang="en">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1021593" xml:lang="en">1021593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33479" xml:lang="en">33479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51395" xml:lang="en">51395</vuln:reference>
    </vuln:references>
    <vuln:summary>PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to obtain the decryption key via unspecified vectors, related to a "logic error."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.5"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.6"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.6</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.5</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0054</vuln:cve-id>
    <vuln:published-datetime>2009-01-16T16:30:03.437-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:49.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-19T15:18:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0140" xml:lang="en">ADV-2009-0140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33268" xml:lang="en">33268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml" xml:lang="en">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1021593" xml:lang="en">1021593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33479" xml:lang="en">33479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51396" xml:lang="en">51396</vuln:reference>
    </vuln:references>
    <vuln:summary>PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to capture credentials by tricking a user into reading a modified or crafted e-mail message.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.5"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.6"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.6</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.5</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0055</vuln:cve-id>
    <vuln:published-datetime>2009-01-16T16:30:03.453-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:50.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-19T15:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0140" xml:lang="en">ADV-2009-0140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33268" xml:lang="en">33268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml" xml:lang="en">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1021594" xml:lang="en">1021594</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33479" xml:lang="en">33479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51397" xml:lang="en">51397</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to modify appliance preferences as arbitrary users via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.5"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.6"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ironport_postx:6.2.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5.0.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.4</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.6</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.5</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.5</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.3.0.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.5</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_encryption_appliance:6.2.7.6</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ironport_postx:6.2.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0056</vuln:cve-id>
    <vuln:published-datetime>2009-01-16T16:30:03.467-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:50.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-19T15:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0140" xml:lang="en">ADV-2009-0140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33268" xml:lang="en">33268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml" xml:lang="en">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1021594" xml:lang="en">1021594</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33479" xml:lang="en">33479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51398" xml:lang="en">51398</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to execute commands and modify appliance preferences as arbitrary users via a logout action.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_4a"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_4a_su1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_4"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_3a"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1%281%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.0_2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1%283c%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1:%283a%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1:5.1_%282a%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1:5.1%281%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1:%282%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1:%282b%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1:%281%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1%282%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1:%282a%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1_3a"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1_2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1_%282a%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1_2b"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1_2a"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:5.1_1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.0:%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.1:%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.0:%281%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.1%282%29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.1_1a"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.0_1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.0_1a"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager:6.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1:5.1%281%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.0_1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_3</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1:%281%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_2</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.0</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1:5.1_%282a%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1:%282%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_4a</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1_2a</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.1.0</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1_1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1:%283a%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.0:%281%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1:%282a%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_4a_su1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_4</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1_%282a%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1_2</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.1%282%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.0:%281a%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1%283c%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.1:%281a%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_3a</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1_3a</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.1_1a</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.0_1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:6.0_1a</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1.2</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1:%282b%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1%282%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1%281%29</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_communications_manager:5.1_2b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0057</vuln:cve-id>
    <vuln:published-datetime>2009-01-22T13:30:03.813-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:50.220-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-22T14:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48139" xml:lang="en">cucm-capf-dos-var1(48139)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0213" xml:lang="en">ADV-2009-0213</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021620" xml:lang="en">1021620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33379" xml:lang="en">33379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a61928.shtml" xml:lang="en">20090121 Cisco Unified Communications Manager CAPF Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33588" xml:lang="en">33588</vuln:reference>
    </vuln:references>
    <vuln:summary>The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6.x before 6.1(3) allows remote attackers to cause a denial of service (voice service outage) by sending malformed input over a TCP session in which the "client terminates prematurely."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:wireless_lan_controller:5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:4400_wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:4400_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:4400_wireless_lan_controller:5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:4400_wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:4400_wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:wireless_lan_controller:5.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:5.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:5.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:5.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:4400_wireless_lan_controller:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0058</vuln:cve-id>
    <vuln:published-datetime>2009-02-04T19:30:00.267-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-06T01:49:09.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.1</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-05T12:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021679" xml:lang="en">1021679</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33608" xml:lang="en">33608</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6c1dd.shtml" xml:lang="en">20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33749" xml:lang="en">33749</vuln:reference>
    </vuln:references>
    <vuln:summary>The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.2 allow remote attackers to cause a denial of service (web authentication outage or device reload) via unspecified network traffic, as demonstrated by a vulnerability scanner.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:wireless_lan_controller:5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:4400_wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:4400_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:4400_wireless_lan_controller:5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:4400_wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:4400_wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:wireless_lan_controller:5.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:5.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:5.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:5.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:4400_wireless_lan_controller:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0059</vuln:cve-id>
    <vuln:published-datetime>2009-02-04T19:30:00.280-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-06T01:49:09.233-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-05T11:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021679" xml:lang="en">1021679</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33608" xml:lang="en">33608</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6c1dd.shtml" xml:lang="en">20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33749" xml:lang="en">33749</vuln:reference>
    </vuln:references>
    <vuln:summary>The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of service (device reload) via a web authentication (aka WebAuth) session that includes a malformed POST request to login.html.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0061">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:4400_wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:4400_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:wireless_lan_controller:5.0"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:4400_wireless_lan_controller:5.0"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:5.0"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:5.0"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:4400_wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:4400_wireless_lan_controller:5.0</vuln:product>
      <vuln:product>cpe:/h:cisco:wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:5.0</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:4400_wireless_lan_controller:4.1</vuln:product>
      <vuln:product>cpe:/h:cisco:wireless_lan_controller:5.0</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_series_wireless_lan_controller:5.0</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_series_integrated_wireless_lan_controller:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0061</vuln:cve-id>
    <vuln:published-datetime>2009-02-04T19:30:00.297-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-06T01:49:09.377-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-05T12:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021679" xml:lang="en">1021679</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33608" xml:lang="en">33608</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6c1dd.shtml" xml:lang="en">20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33749" xml:lang="en">33749</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Wireless LAN Controller (WLC) TSEC driver in the Cisco 4400 WLC, Cisco Catalyst 6500 and 7600 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.1 allows remote attackers to cause a denial of service (device crash or hang) via unknown IP packets.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0062">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:wireless_lan_controller:4.2.173.0"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.2.173.0"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_wireless_services_modules:4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_wireless_services_modules:4.2.173.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:catalyst_6500_wireless_services_modules:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:wireless_lan_controller:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_wireless_services_modules:4.2.173.0</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.2.173.0</vuln:product>
      <vuln:product>cpe:/h:cisco:wireless_lan_controller:4.2.173.0</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_3750_series_integrated_wireless_lan_controller:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0062</vuln:cve-id>
    <vuln:published-datetime>2009-02-04T19:30:00.327-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-06T01:49:09.500-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-05T12:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021678" xml:lang="en">1021678</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33608" xml:lang="en">33608</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6c1dd.shtml" xml:lang="en">20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33749" xml:lang="en">33749</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.2.173.0 allows remote authenticated users to gain privileges via unknown vectors, as demonstrated by escalation from the (1) Lobby Admin and (2) Local Management User privilege levels.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:symantec:brightmail_gateway_appliance:7.7"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:brightmail_gateway_appliance:7.6"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:brightmail_gateway_appliance:7.5"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:brightmail_gateway_appliance:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:symantec:brightmail_gateway_appliance:7.5</vuln:product>
      <vuln:product>cpe:/h:symantec:brightmail_gateway_appliance:7.6</vuln:product>
      <vuln:product>cpe:/h:symantec:brightmail_gateway_appliance:8.0</vuln:product>
      <vuln:product>cpe:/h:symantec:brightmail_gateway_appliance:7.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0063</vuln:cve-id>
    <vuln:published-datetime>2009-04-24T11:30:00.187-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T23:13:43.563-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-24T13:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1155" xml:lang="en">ADV-2009-1155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1022116" xml:lang="en">1022116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/50074" xml:lang="en">brightmail-controlcenter-xss(50074)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090423_01" xml:lang="en">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090423_01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34641" xml:lang="en">34641</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34885" xml:lang="en">34885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/53944" xml:lang="en">53944</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:symantec:brightmail_gateway_appliance:8.0"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:brightmail_gateway_appliance:7.7"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:brightmail_gateway_appliance:7.6"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:brightmail_gateway_appliance:7.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:symantec:brightmail_gateway_appliance:7.5</vuln:product>
      <vuln:product>cpe:/h:symantec:brightmail_gateway_appliance:7.6</vuln:product>
      <vuln:product>cpe:/h:symantec:brightmail_gateway_appliance:8.0</vuln:product>
      <vuln:product>cpe:/h:symantec:brightmail_gateway_appliance:7.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0064</vuln:cve-id>
    <vuln:published-datetime>2009-04-24T11:30:00.203-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T23:13:43.767-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-24T13:55:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1155" xml:lang="en">ADV-2009-1155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1022117" xml:lang="en">1022117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/50075" xml:lang="en">brightmail-consolescripts-priv-escalation(50075)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090423_01" xml:lang="en">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090423_01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34639" xml:lang="en">34639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34885" xml:lang="en">34885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/53945" xml:lang="en">53945</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allow remote authenticated users to gain privileges, and possibly obtain sensitive information or hijack sessions of arbitrary users, via vectors involving (1) administrative scripts or (2) console functions.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.12::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.11::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.8::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.7::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.6::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.5::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.4::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.3::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.2::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.10::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.9::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.5::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.6::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.9::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.3::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.7::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.2::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.10::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.8::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.11::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.12::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.4::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.1::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0065</vuln:cve-id>
    <vuln:published-datetime>2009-01-07T14:30:00.280-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-08T07:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10872" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10872" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01045.html" xml:lang="en">FEDORA-2009-0816</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=478800" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=478800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/2193" xml:lang="en">ADV-2009-2193</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0029" xml:lang="en">ADV-2009-0029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-751-1" xml:lang="en">USN-751-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022698" xml:lang="en">1022698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33113" xml:lang="en">33113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-1055.html" xml:lang="en">RHSA-2009:1055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0331.html" xml:lang="en">RHSA-2009:0331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0053.html" xml:lang="en">RHSA-2009:0053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2009/01/05/1" xml:lang="en">[oss-security] 20090105 CVE request: kernel: sctp: memory overflow when FWD-TSN chunk is received with bad stream ID</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1794" xml:lang="en">DSA-1794</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1787" xml:lang="en">DSA-1787</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1749" xml:lang="en">DSA-1749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/36191" xml:lang="en">36191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35394" xml:lang="en">35394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35390" xml:lang="en">35390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35174" xml:lang="en">35174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35011" xml:lang="en">35011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34981" xml:lang="en">34981</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34762" xml:lang="en">34762</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34680" xml:lang="en">34680</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34394" xml:lang="en">34394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34252" xml:lang="en">34252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33858" xml:lang="en">33858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33854" xml:lang="en">33854</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33674" xml:lang="en">33674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2009-0264.html" xml:lang="en">RHSA-2009:0264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://patchwork.ozlabs.org/patch/15024/" xml:lang="en">http://patchwork.ozlabs.org/patch/15024/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" xml:lang="en">SUSE-SA:2009:031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" xml:lang="en">SUSE-SA:2009:030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" xml:lang="en">SUSE-SA:2009:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01832118" xml:lang="en">SSSRT090149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01832118" xml:lang="en">SSSRT090149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9fcb95a105758b81ef0131cd18e2db5149f13e95" xml:lang="en">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9fcb95a105758b81ef0131cd18e2db5149f13e95</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10872" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10872" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 allows remote attackers to have an unknown impact via an FWD-TSN (aka FORWARD-TSN) chunk with a large stream ID.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:intel:trusted_execution_technology:_nil_"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:intel:trusted_execution_technology:_nil_</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0066</vuln:cve-id>
    <vuln:published-datetime>2009-01-07T14:30:00.297-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-08T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-08T08:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33119" xml:lang="en">33119</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://theinvisiblethings.blogspot.com/2009/01/attacking-intel-trusted-execution.html" xml:lang="en">http://theinvisiblethings.blogspot.com/2009/01/attacking-intel-trusted-execution.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://invisiblethingslab.com/press/itl-press-2009-01.pdf" xml:lang="en">http://invisiblethingslab.com/press/itl-press-2009-01.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Wojtczuk" xml:lang="en">http://blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Wojtczuk</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Intel system software for Trusted Execution Technology (TXT) allow attackers to bypass intended loader integrity protections, as demonstrated by exploitation of tboot.  NOTE: as of 20090107, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:freedesktop:xdg-utils:1.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:freedesktop:xdg-utils:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0068</vuln:cve-id>
    <vuln:published-datetime>2009-01-07T14:30:00.313-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-02-10T01:59:42.920-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-08T08:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugs.freedesktop.org/show_bug.cgi?id=19377" xml:lang="en">https://bugs.freedesktop.org/show_bug.cgi?id=19377</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33137" xml:lang="en">33137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2009/01/06/1" xml:lang="en">[oss-security] 20090106 Fwd: Using xdg-open in /etc/mailcap causes hole in Firefox (Demonstration/Exploit included)</vuln:reference>
    </vuln:references>
    <vuln:summary>Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_02::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_07::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_01::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_08::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_04::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_05::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_03::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_06::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_09::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_10::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_101::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_15::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_13::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_100::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_14::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_11::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_12::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_104::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_21::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_20::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_19::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_25::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_17::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_24::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_23::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_18::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_16::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_22::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_28::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_33::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_27::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_34::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_26::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_35::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_32::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_31::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_30::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_29::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_40::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_41::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_42::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_36::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_43::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_37::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_44::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_38::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_45::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_39::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_48::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_55::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_47::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_54::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_50::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_49::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_52::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_51::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_53::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_46::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_57::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_56::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_59::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_65::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_58::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_64::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_61::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_63::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_60::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_62::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_71::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_68::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_72::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_67::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_70::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_66::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_74::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_73::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_69::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_75::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_78::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_84::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_77::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_83::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_79::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_85::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_80::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_76::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_82::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_81::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_86::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_87::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_88::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_89::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_90::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_91::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_92::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_93::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_94::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_95::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_99::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_98::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_97::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_96::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_03::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_08::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_02::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_09::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_05::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_06::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_04::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_07::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_01::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_10::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_101::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_100::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_11::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_12::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_13::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_14::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_15::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_21::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_20::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_19::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_25::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_24::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_18::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_23::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_16::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_17::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_22::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_28::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_27::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_33::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_26::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_34::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_35::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_32::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_31::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_30::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_29::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_40::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_41::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_42::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_43::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_36::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_44::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_37::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_45::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_38::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_39::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_48::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_47::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_55::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_50::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_49::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_52::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_51::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_54::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_46::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_53::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_57::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_56::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_59::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_65::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_58::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_64::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_61::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_63::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_60::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_62::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_68::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_71::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_67::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_72::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_66::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_70::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_74::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_73::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_75::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_69::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_78::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_85::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_77::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_84::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_79::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_81::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_80::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_76::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_83::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_82::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_87::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_88::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_86::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_92::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_91::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_90::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_89::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_95::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_94::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_93::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_99::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_97::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_98::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_96::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:opensolaris:snv_48::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_02::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_04::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_10::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_62::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_99::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_57::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_27::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_66::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_11::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_06::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_45::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_70::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_24::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_41::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_68::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_42::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_74::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_04::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_70::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_98::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_30::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_79::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_100::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_56::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_31::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_20::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_56::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_01::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_79::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_96::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_88::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_24::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_28::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_36::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_73::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_64::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_57::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_91::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_25::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_47::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_19::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_32::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_53::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_69::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_05::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_65::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_90::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_44::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_34::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_12::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_32::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_97::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_01::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_101::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_27::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_97::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:10::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_54::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_66::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_51::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_61::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_52::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_05::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_93::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_37::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_29::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_09::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_10::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_59::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_63::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_26::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_73::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_47::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_12::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_69::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_85::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_40::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_50::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_77::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_77::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_71::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_14::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:10::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_89::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_93::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_29::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_21::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_61::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_67::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_92::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_90::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_81::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_46::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_59::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_50::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_37::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_83::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_81::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_31::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_45::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_19::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_76::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_75::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_67::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_86::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_52::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_76::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_14::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_17::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_75::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_49::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_35::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_26::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_65::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_87::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_94::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_74::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_78::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_100::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_72::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_98::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_28::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_07::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_46::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_54::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_02::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_94::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_60::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_41::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_22::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_68::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_38::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_09::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_51::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_25::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_23::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_95::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_36::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_33::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_18::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_30::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_13::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_40::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_88::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_86::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_20::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_91::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_63::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_23::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_92::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_82::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_49::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_06::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_53::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_64::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_60::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_78::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_80::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_55::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_71::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_95::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_08::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_43::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_83::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_96::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_43::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_34::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_48::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_15::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_87::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_104::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_03::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_84::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_80::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_44::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_39::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_18::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_13::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_03::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_99::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_22::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_62::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_101::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_17::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_85::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_58::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_21::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_72::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_38::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_08::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_55::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_42::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_07::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_16::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_82::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_16::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_15::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_39::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_58::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_84::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_33::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_35::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_89::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_11::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0069</vuln:cve-id>
    <vuln:published-datetime>2009-01-07T15:30:00.467-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:51.203-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-08T09:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139466-02-1" xml:lang="en">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139466-02-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/47750" xml:lang="en">solaris-nfs4client-dos(47750)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0030" xml:lang="en">ADV-2009-0030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021519" xml:lang="en">1021519</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33128" xml:lang="en">33128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-248566-1" xml:lang="en">248566</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33361" xml:lang="en">33361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://mail.opensolaris.org/pipermail/onnv-notify/2008-October/015342.html" xml:lang="en">[onnv-notify] 20081021 6300710 recursive mutex_enter in nfs4rename_persistent_fh()</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the nfs4rename_persistent_fh function in the NFS 4 (aka NFSv4) client in the kernel in Sun Solaris 10 and OpenSolaris before snv_102 allows local users to cause a denial of service (recursive mutex_enter and panic) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0070">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0070</vuln:cve-id>
    <vuln:published-datetime>2009-01-08T14:30:11.280-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T02:00:57.390-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T09:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48214" xml:lang="en">safari-array-memory-disclosure(48214)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/7673" xml:lang="en">7673</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array in a JavaScript function, possibly a related issue to CVE-2008-2307.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0:beta5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0:beta5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0071</vuln:cve-id>
    <vuln:published-datetime>2009-01-08T14:30:11.297-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-25T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T10:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=472507" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=472507</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=456727" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=456727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=448329" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=448329</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33154" xml:lang="en">33154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/8219" xml:lang="en">8219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/8091" xml:lang="en">8091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0224.html" xml:lang="en">20090107 Re: Firefox 3.0.5 remote vulnerability via queryCommandState</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0223.html" xml:lang="en">20090107 Re: Firefox 3.0.5 remote vulnerability via queryCommandState</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0220.html" xml:lang="en">20090107 Firefox 3.0.5 remote vulnerability via queryCommandState</vuln:reference>
    </vuln:references>
    <vuln:summary>Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call.  NOTE: it was later reported that 3.0.6 and 3.0.7 are also affected.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8:beta1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8:beta2</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8:beta1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0072</vuln:cve-id>
    <vuln:published-datetime>2009-01-08T14:30:11.313-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-09T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T10:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/47788" xml:lang="en">ie-javascript-screen-dos(47788)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33149" xml:lang="en">33149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://skypher.com/index.php/2009/01/07/msie-screen-null-ptr-dos-details/" xml:lang="en">http://skypher.com/index.php/2009/01/07/msie-screen-null-ptr-dos-details/</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application crash) via an onload=screen[""] attribute value in a BODY element.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0075</vuln:cve-id>
    <vuln:published-datetime>2009-02-10T17:30:00.250-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-30T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-11T09:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6000" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6000" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" xml:lang="en">TA09-041A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-002.mspx" xml:lang="en">MS09-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-09-011/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-09-011/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0389" xml:lang="en">ADV-2009-0389</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33627" xml:lang="en">33627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/8082" xml:lang="en">8082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/8080" xml:lang="en">8080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/8079" xml:lang="en">8079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/8077" xml:lang="en">8077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51839" xml:lang="en">51839</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6000" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6000" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, aka "Uninitialized Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0076</vuln:cve-id>
    <vuln:published-datetime>2009-02-10T17:30:00.267-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-06T01:49:11.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-11T10:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6081" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6081" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" xml:lang="en">TA09-041A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-002.mspx" xml:lang="en">MS09-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-09-012/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-09-012/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0389" xml:lang="en">ADV-2009-0389</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6081" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6081" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conjunction with unspecified other directives in a malformed Cascading Style Sheets (CSS) stylesheet in a crafted HTML document, aka "CSS Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:forefront_threat_management_gateway:-:-:medium_business"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_security_and_acceleration_server:2004:sp3:standard"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_security_and_acceleration_server:2004:sp3:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_security_and_acceleration_server:2006:supportability"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_security_and_acceleration_server:2006:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_security_and_acceleration_server:2004:sp3:enterprise</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_security_and_acceleration_server:2004:sp3:standard</vuln:product>
      <vuln:product>cpe:/a:microsoft:forefront_threat_management_gateway:-:-:medium_business</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_security_and_acceleration_server:2006:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_security_and_acceleration_server:2006:supportability</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0077</vuln:cve-id>
    <vuln:published-datetime>2009-04-15T04:00:00.267-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:41.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-15T08:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6068" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6068" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" xml:lang="en">TA09-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-016.mspx" xml:lang="en">MS09-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1030" xml:lang="en">ADV-2009-1030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022045" xml:lang="en">1022045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34687" xml:lang="en">34687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/53636" xml:lang="en">53636</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6068" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6068" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a denial of service (many stale sessions) via crafted packets, aka "Web Proxy TCP State Limited Denial of Service Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::pro_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:pro_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::32_bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::pro_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::32_bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:pro_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0078</vuln:cve-id>
    <vuln:published-datetime>2009-04-15T04:00:00.327-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:41.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-15T08:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6193" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6193" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" xml:lang="en">TA09-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-012.mspx" xml:lang="en">MS09-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1026" xml:lang="en">ADV-2009-1026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022044" xml:lang="en">1022044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/53666" xml:lang="en">53666</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6193" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6193" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::pro_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:pro_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::pro_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:pro_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0079</vuln:cve-id>
    <vuln:published-datetime>2009-04-15T04:00:00.377-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:41.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-15T09:02:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6147" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6147" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" xml:lang="en">TA09-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-012.mspx" xml:lang="en">MS09-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1026" xml:lang="en">ADV-2009-1026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022044" xml:lang="en">1022044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/53667" xml:lang="en">53667</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6147" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6147" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server:2008:-:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server:2008:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server:2008:-:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server:2008:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server:2008:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server:2008:-:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0080</vuln:cve-id>
    <vuln:published-datetime>2009-04-15T04:00:00.407-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:41.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-15T09:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6177" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6177" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" xml:lang="en">TA09-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-012.mspx" xml:lang="en">MS09-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1026" xml:lang="en">ADV-2009-1026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022044" xml:lang="en">1022044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/53668" xml:lang="en">53668</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6177" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6177" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by leveraging incorrect thread ACLs to access the resources of one of the processes, aka "Windows Thread Pool ACL Weakness Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0081</vuln:cve-id>
    <vuln:published-datetime>2009-03-10T16:30:00.343-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:41.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-03-11T08:26:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6202" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6202" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" xml:lang="en">TA09-069A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-006.mspx" xml:lang="en">MS09-006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0659" xml:lang="en">ADV-2009-0659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021826" xml:lang="en">1021826</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34012" xml:lang="en">34012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=" xml:lang="en">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34117" xml:lang="en">34117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/52522" xml:lang="en">52522</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6202" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6202" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows Metafile (aka WMF) or (2) Enhanced Metafile (aka EMF) image file, aka "Windows Kernel Input Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0082</vuln:cve-id>
    <vuln:published-datetime>2009-03-10T16:30:01.483-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:41.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-03-11T08:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6036" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6036" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" xml:lang="en">TA09-069A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0659" xml:lang="en">ADV-2009-0659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021827" xml:lang="en">1021827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34027" xml:lang="en">34027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-006.mspx" xml:lang="en">MS09-006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=" xml:lang="en">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34117" xml:lang="en">34117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/52523" xml:lang="en">52523</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6036" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6036" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0083</vuln:cve-id>
    <vuln:published-datetime>2009-03-10T16:30:06.500-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:42.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-03-11T08:52:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5440" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5440" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" xml:lang="en">TA09-069A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-006.mspx" xml:lang="en">MS09-006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0659" xml:lang="en">ADV-2009-0659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021827" xml:lang="en">1021827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34025" xml:lang="en">34025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=" xml:lang="en">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34117" xml:lang="en">34117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/52524" xml:lang="en">52524</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5440" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5440" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:8.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:9.0a"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:9.0b"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:directx:9.0c"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::pro_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:pro_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:directx:9.0a</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:9.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:9.0b</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:9.0c</vuln:product>
      <vuln:product>cpe:/a:microsoft:directx:8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0084</vuln:cve-id>
    <vuln:published-datetime>2009-04-15T04:00:00.420-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:42.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-15T09:18:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5618" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5618" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" xml:lang="en">TA09-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-011.mspx" xml:lang="en">MS09-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1025" xml:lang="en">ADV-2009-1025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022040" xml:lang="en">1022040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34460" xml:lang="en">34460</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.piotrbania.com/all/adv/ms-directx-mjpeg-adv.txt" xml:lang="en">http://www.piotrbania.com/all/adv/ms-directx-mjpeg-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2009-132.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2009-132.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34665" xml:lang="en">34665</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/53632" xml:lang="en">53632</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5618" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5618" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or video stream with a malformed Huffman table, which triggers an exception that frees heap memory that is later accessed, aka "MJPEG Decompression Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0085</vuln:cve-id>
    <vuln:published-datetime>2009-03-10T16:30:06.530-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:42.400-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-03-11T08:59:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6011" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6011" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" xml:lang="en">TA09-069A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-007.mspx" xml:lang="en">MS09-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0660" xml:lang="en">ADV-2009-0660</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021828" xml:lang="en">1021828</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34215" xml:lang="en">34215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/52521" xml:lang="en">52521</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6011" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6011" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake messages, which allows remote attackers to spoof authentication by crafting a TLS packet based on knowledge of the certificate but not the private key, aka "SChannel Spoofing Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::32_bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::32_bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0086</vuln:cve-id>
    <vuln:published-datetime>2009-04-15T04:00:00.453-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:42.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-15T09:25:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6149" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6149" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" xml:lang="en">TA09-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-013.mspx" xml:lang="en">MS09-013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1027" xml:lang="en">ADV-2009-1027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022041" xml:lang="en">1022041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34435" xml:lang="en">34435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34677" xml:lang="en">34677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/53620" xml:lang="en">53620</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6149" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6149" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows:2000:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::pro_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:pro_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_srv:2003:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_srv:2003:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_srv:2003:sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_srv:2003:sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_word:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_word:2002:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_srv:2003:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_srv:2003:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server:2003:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::pro_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_srv:2003:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_srv:2003:sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server:2003:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:pro_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows:2000:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_word:2000:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_word:2002:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0087</vuln:cve-id>
    <vuln:published-datetime>2009-04-15T04:00:00.467-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:42.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-15T09:38:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5799" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5799" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" xml:lang="en">TA09-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-010.mspx" xml:lang="en">MS09-010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1024" xml:lang="en">ADV-2009-1024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022043" xml:lang="en">1022043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/53662" xml:lang="en">53662</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5799" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5799" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and the Word 6 text converter in Microsoft Office Word 2000 SP3 and 2002 SP3; allows remote attackers to execute arbitrary code via a crafted Word 6 file that contains malformed data, aka "WordPad and Office Text Converter Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office_converter_pack:2003"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office_word:2002:sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office_word:2000:sp3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:pro_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::pro_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::pro_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:pro_x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_word:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_converter_pack:2003</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_word:2002:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0088</vuln:cve-id>
    <vuln:published-datetime>2009-04-15T04:00:00.483-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:42.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-15T09:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5736" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5736" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" xml:lang="en">TA09-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-010.mspx" xml:lang="en">MS09-010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1024" xml:lang="en">ADV-2009-1024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022043" xml:lang="en">1022043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/53663" xml:lang="en">53663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=782" xml:lang="en">20090414 Microsoft Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5736" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5736" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:pro_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::pro_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::pro_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:pro_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0089</vuln:cve-id>
    <vuln:published-datetime>2009-04-15T04:00:00.517-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:43.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-15T09:48:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6027" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6027" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" xml:lang="en">TA09-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-013.mspx" xml:lang="en">MS09-013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1027" xml:lang="en">ADV-2009-1027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022041" xml:lang="en">1022041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34437" xml:lang="en">34437</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34677" xml:lang="en">34677</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6027" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6027" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0090">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0:sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0090</vuln:cve-id>
    <vuln:published-datetime>2009-10-14T06:30:00.420-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:43.150-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-10-14T09:03:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5716" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5716" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-286A.html" xml:lang="en">TA09-286A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-061.mspx" xml:lang="en">MS09-061</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5716" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5716" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0:sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5:sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0091</vuln:cve-id>
    <vuln:published-datetime>2009-10-14T06:30:00.483-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:43.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-10-14T10:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6451" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6451" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-286A.html" xml:lang="en">TA09-286A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-061.mspx" xml:lang="en">MS09-061</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6451" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6451" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2008</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0093</vuln:cve-id>
    <vuln:published-datetime>2009-03-11T10:19:15.233-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:43.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-03-11T10:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6138" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6138" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" xml:lang="en">TA09-069A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx" xml:lang="en">MS09-008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0661" xml:lang="en">ADV-2009-0661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021830" xml:lang="en">1021830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33989" xml:lang="en">33989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34217" xml:lang="en">34217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/52519" xml:lang="en">52519</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx" xml:lang="en">http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blog.ncircle.com/blogs/vert/archives/2009/03/successful_exploit_renders_mic.html" xml:lang="en">http://blog.ncircle.com/blogs/vert/archives/2009/03/successful_exploit_renders_mic.html</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6138" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6138" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2008</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0094</vuln:cve-id>
    <vuln:published-datetime>2009-03-11T10:19:15.250-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:43.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-03-11T10:54:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6117" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6117" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" xml:lang="en">TA09-069A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx" xml:lang="en">MS09-008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0661" xml:lang="en">ADV-2009-0661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021829" xml:lang="en">1021829</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34013" xml:lang="en">34013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34217" xml:lang="en">34217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/52520" xml:lang="en">52520</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx" xml:lang="en">http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6117" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6117" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2002:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2007:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:visio:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2007:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2002:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0095</vuln:cve-id>
    <vuln:published-datetime>2009-02-10T17:30:00.280-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:53.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-11T10:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6179" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6179" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" xml:lang="en">TA09-041A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-005.mspx" xml:lang="en">MS09-005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0391" xml:lang="en">ADV-2009-0391</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6179" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6179" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2002:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2007:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:visio:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2007:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2002:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0096</vuln:cve-id>
    <vuln:published-datetime>2009-02-10T17:30:00.313-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:53.627-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-11T10:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6172" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6172" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" xml:lang="en">TA09-041A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0391" xml:lang="en">ADV-2009-0391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-005.mspx" xml:lang="en">MS09-005</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6172" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6172" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka "Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2002:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2007:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:visio:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2007:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2002:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0097</vuln:cve-id>
    <vuln:published-datetime>2009-02-10T17:30:00.327-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:53.720-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-11T10:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6188" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6188" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" xml:lang="en">TA09-041A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-005.mspx" xml:lang="en">MS09-005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0391" xml:lang="en">ADV-2009-0391</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6188" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6188" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0098">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2007:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2007:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0098</vuln:cve-id>
    <vuln:published-datetime>2009-02-10T17:30:00.343-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-04T01:48:28.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-11T10:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6114" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6114" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" xml:lang="en">TA09-041A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-003.mspx" xml:lang="en">MS09-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33838" xml:lang="en">33838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51837" xml:lang="en">51837</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6114" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6114" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0099">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2007:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2007:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0099</vuln:cve-id>
    <vuln:published-datetime>2009-02-10T17:30:00.377-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-04T01:48:28.233-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-11T10:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6159" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6159" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" xml:lang="en">TA09-041A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-003.mspx" xml:lang="en">MS09-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33838" xml:lang="en">33838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51838" xml:lang="en">51838</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6159" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6159" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0100">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2008::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_excel_viewer"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_excel_viewer:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007::sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_excel:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_excel:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_excel:2007:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_excel:2002:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office_excel_viewer</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_excel:2007:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_excel:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_excel:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2008::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_excel:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007::sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_excel_viewer:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0100</vuln:cve-id>
    <vuln:published-datetime>2009-04-15T04:00:00.530-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:44.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-15T10:07:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6043" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6043" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" xml:lang="en">TA09-104A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-009.mspx" xml:lang="en">MS09-009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1023" xml:lang="en">ADV-2009-1023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022039" xml:lang="en">1022039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/502696/100/0/threaded" xml:lang="en">20090415 Microsoft Office Excel Remote Memory Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.fortiguardcenter.com/advisory/FGA-2009-16.html" xml:lang="en">http://www.fortiguardcenter.com/advisory/FGA-2009-16.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/53665" xml:lang="en">53665</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6043" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6043" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel in Microsoft Office 2004 and 2008 for Mac; Microsoft Office Excel Viewer and Excel Viewer 2003 SP3; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 do not properly parse the Excel spreadsheet file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that contains a malformed object with "an offset and a two-byte value" that trigger a memory calculation error, aka "Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0102">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_project:2007:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_project:2007:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project_server:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project_server:2007:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project_server:2007:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project_portfolio_server:2007:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project_portfolio_server:2007:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:project_server:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_project:2007:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_project:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:project_server:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:project_portfolio_server:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:project_portfolio_server:2007:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:project_server:2007:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0102</vuln:cve-id>
    <vuln:published-datetime>2009-12-09T13:30:00.203-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:44.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-12-10T07:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6298" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6298" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-342A.html" xml:lang="en">TA09-342A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS09-074.mspx" xml:lang="en">MS09-074</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6298" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6298" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0103">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:playsms:playsms:0.9.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:playsms:playsms:0.9.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0103</vuln:cve-id>
    <vuln:published-datetime>2009-01-09T13:30:03.047-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T02:00:58.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T15:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33138" xml:lang="en">33138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/7687" xml:lang="en">7687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4888" xml:lang="en">4888</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33386" xml:lang="en">33386</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_path[plug] parameter to plugin/gateway/gnokii/init.php, the (2) apps_path[themes] parameter to plugin/themes/default/init.php, and the (3) apps_path[libs] parameter to lib/function.php.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:se-ed:ezpack:4.2:beta2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:se-ed:ezpack:4.2:beta2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0104</vuln:cve-id>
    <vuln:published-datetime>2009-01-09T13:30:03.063-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T02:00:58.390-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T15:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33131" xml:lang="en">33131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/7680" xml:lang="en">7680</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4890" xml:lang="en">4890</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via the qType parameter in a webboard prog action.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0105">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:se-ed:ezpack:4.2:beta2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:se-ed:ezpack:4.2:beta2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0105</vuln:cve-id>
    <vuln:published-datetime>2009-01-09T13:30:03.077-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T02:00:58.610-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T15:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33131" xml:lang="en">33131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/7680" xml:lang="en">7680</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4890" xml:lang="en">4890</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd parameter in a prog action.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0106">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpauctions:phpauctions:_nil_"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpauctions:phpauctions:_nil_</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0106</vuln:cve-id>
    <vuln:published-datetime>2009-01-09T13:30:03.093-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-04-10T01:32:32.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T15:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/43264" xml:lang="en">phpauctions-profile-sql-injection(43264)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33115" xml:lang="en">33115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33331" xml:lang="en">33331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51144" xml:lang="en">51144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/7672" xml:lang="en">7672</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpauctions:phpauctions:_nil_"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpauctions:phpauctions:_nil_</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0107</vuln:cve-id>
    <vuln:published-datetime>2009-01-09T13:30:03.127-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-09T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T15:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33115" xml:lang="en">33115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33331" xml:lang="en">33331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51145" xml:lang="en">51145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://milw0rm.com/exploits/7672" xml:lang="en">7672</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:phpauctions:phpauctions:_nil_"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpauctions:phpauctions:_nil_</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0108</vuln:cve-id>
    <vuln:published-datetime>2009-01-09T13:30:03.140-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T16:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33120" xml:lang="en">33120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/7674" xml:lang="en">7674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4891" xml:lang="en">4891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33331" xml:lang="en">33331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/51146" xml:lang="en">51146</vuln:reference>
    </vuln:references>
    <vuln:summary>PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID, (2) PHPAUCTION_RM_NAME, (3) PHPAUCTION_RM_USERNAME, and (4) PHPAUCTION_RM_EMAIL cookies.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.61"/>
        <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.52"/>
        <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.51:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:.05"/>
        <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:riotpix:riotpix:.05</vuln:product>
      <vuln:product>cpe:/a:riotpix:riotpix:0.51:beta</vuln:product>
      <vuln:product>cpe:/a:riotpix:riotpix:0.61</vuln:product>
      <vuln:product>cpe:/a:riotpix:riotpix:0.5</vuln:product>
      <vuln:product>cpe:/a:riotpix:riotpix:0.60</vuln:product>
      <vuln:product>cpe:/a:riotpix:riotpix:0.52</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0109</vuln:cve-id>
    <vuln:published-datetime>2009-01-09T13:30:03.157-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T02:00:59.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T16:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33132" xml:lang="en">33132</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/7682" xml:lang="en">7682</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4892" xml:lang="en">4892</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33395" xml:lang="en">33395</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.61"/>
        <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.52"/>
        <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.51:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:.05"/>
        <cpe-lang:fact-ref name="cpe:/a:riotpix:riotpix:0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:riotpix:riotpix:.05</vuln:product>
      <vuln:product>cpe:/a:riotpix:riotpix:0.51:beta</vuln:product>
      <vuln:product>cpe:/a:riotpix:riotpix:0.61</vuln:product>
      <vuln:product>cpe:/a:riotpix:riotpix:0.5</vuln:product>
      <vuln:product>cpe:/a:riotpix:riotpix:0.60</vuln:product>
      <vuln:product>cpe:/a:riotpix:riotpix:0.52</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0110</vuln:cve-id>
    <vuln:published-datetime>2009-01-09T13:30:03.170-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T02:00:59.467-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T16:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33129" xml:lang="en">33129</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/7679" xml:lang="en">7679</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4893" xml:lang="en">4893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33395" xml:lang="en">33395</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:goople_cms:goople_cms:1.8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:goople_cms:goople_cms:1.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0111</vuln:cve-id>
    <vuln:published-datetime>2009-01-09T13:30:03.203-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T02:00:59.640-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T16:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33135" xml:lang="en">33135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/7683" xml:lang="en">7683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4894" xml:lang="en">4894</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33393" xml:lang="en">33393</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:expinion:poll_pro:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:expinion:poll_pro:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0112</vuln:cve-id>
    <vuln:published-datetime>2009-01-09T13:30:03.217-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T02:00:59.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T17:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/47754" xml:lang="en">pollpro-unspecified-csrf(47754)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4895" xml:lang="en">4895</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33319" xml:lang="en">33319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=123117044713213&amp;w=2" xml:lang="en">20090103 PollPro 3.0 XSRF VuLn</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in admin/agent_edit.asp in PollPro 3.0 allows remote attackers to create or modify accounts as administrators via the username, password, and name parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:joomla:xstandard"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.6"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.14"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.13"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.03"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.4"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.5"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.8"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.0:beta"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.0:rc1"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.0:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.0:beta2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:joomla:xstandard</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0113</vuln:cve-id>
    <vuln:published-datetime>2009-01-09T13:30:03.233-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T02:01:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-09T17:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33143" xml:lang="en">33143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/7691" xml:lang="en">7691</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4896" xml:lang="en">4896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33377" xml:lang="en">33377</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the X_CMS_LIBRARY_PATH HTTP header.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.48.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.47.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.45.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.31.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.28.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.28"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.20.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.20"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.16"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.124.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.115.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.114.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.112.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.12.36"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player_for_linux:10.0.15.3"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:air:1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:cs3::pro"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:cs4::pro"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flex:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.0.584"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.12.10"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.63"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.63::linux"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.69.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.70.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.24.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.34.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.35.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.39.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0::basic"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0::pro"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.25"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:flash_player:cs4::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:flex:3.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.16</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.24.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.0.12.10</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.0.12.36</vuln:product>
      <vuln:product>cpe:/a:adobe:air:1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.47.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.0.0.584</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.124.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.63</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.34.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0::basic</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:cs3::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.28</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.2</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.28.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player_for_linux:10.0.15.3</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.114.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.31.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.35.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.25</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.20</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.48.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.1</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.112.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.70.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.20.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.39.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.63::linux</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.45.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.115.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.69.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0114</vuln:cve-id>
    <vuln:published-datetime>2009-02-26T11:17:19.797-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:45.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-26T14:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6662" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6662" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" xml:lang="en">TA09-133A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0513" xml:lang="en">ADV-2009-0513</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb09-01.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb09-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48902" xml:lang="en">flash-settings-manager-click-hijacking(48902)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1297" xml:lang="en">ADV-2009-1297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0743" xml:lang="en">ADV-2009-0743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3549" xml:lang="en">http://support.apple.com/kb/HT3549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254909-1" xml:lang="en">254909</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1021751" xml:lang="en">1021751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200903-23.xml" xml:lang="en">GLSA-200903-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35074" xml:lang="en">35074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34293" xml:lang="en">34293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34226" xml:lang="en">34226</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" xml:lang="en">APPLE-SA-2009-05-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isc.sans.org/diary.html?storyid=5929" xml:lang="en">http://isc.sans.org/diary.html?storyid=5929</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6662" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6662" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL via unknown vectors, related to "a potential Clickjacking issue variant."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:christophe.varoqui:multipath-tools:0.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:christophe.varoqui:multipath-tools:0.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0115</vuln:cve-id>
    <vuln:published-datetime>2009-03-30T12:30:00.343-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:45.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-03-30T13:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9214" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9214" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00236.html" xml:lang="en">FEDORA-2009-3453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00231.html" xml:lang="en">FEDORA-2009-3449</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0528" xml:lang="en">ADV-2010-0528</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1767" xml:lang="en">DSA-1767</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2009-128.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2009-128.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38794" xml:lang="en">38794</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34759" xml:lang="en">34759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34710" xml:lang="en">34710</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34694" xml:lang="en">34694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34642" xml:lang="en">34642</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34418" xml:lang="en">34418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.vmware.com/pipermail/security-announce/2010/000082.html" xml:lang="en">[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" xml:lang="en">SUSE-SR:2009:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" xml:lang="en">SUSE-SR:2009:007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://launchpad.net/bugs/cve/2009-0115" xml:lang="en">http://launchpad.net/bugs/cve/2009-0115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://download.opensuse.org/update/10.3-test/repodata/patch-kpartx-6082.xml" xml:lang="en">http://download.opensuse.org/update/10.3-test/repodata/patch-kpartx-6082.xml</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9214" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9214" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0119</vuln:cve-id>
    <vuln:published-datetime>2009-01-14T18:30:04.377-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T02:01:00.217-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-15T09:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33204" xml:lang="en">33204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/7720" xml:lang="en">7720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4912" xml:lang="en">4912</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:ibm:websphere_datapower_xml_security_gateway_xs40:3.6.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:ibm:websphere_datapower_xml_security_gateway_xs40:3.6.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0120</vuln:cve-id>
    <vuln:published-datetime>2009-01-14T19:30:00.280-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:55.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-15T10:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0111" xml:lang="en">ADV-2009-0111</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021547" xml:lang="en">1021547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33169" xml:lang="en">33169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499870/100/0/threaded" xml:lang="en">20090108 [IBM Datapower XS40] Denial of Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4911" xml:lang="en">4911</vuln:reference>
    </vuln:references>
    <vuln:summary>The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0121">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:goople_cms:goople_cms:1.8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:goople_cms:goople_cms:1.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0121</vuln:cve-id>
    <vuln:published-datetime>2009-01-14T19:30:00.327-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-15T11:05:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33393" xml:lang="en">33393</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:hplip:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:hplip:2.8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:hplip:2.8.2</vuln:product>
      <vuln:product>cpe:/a:hp:hplip:2.7.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0122</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.483-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-31T01:54:38.047-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T09:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33249" xml:lang="en">33249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://launchpad.net/bugs/191299" xml:lang="en">https://launchpad.net/bugs/191299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-708-1" xml:lang="en">USN-708-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33539" xml:lang="en">33539</vuln:reference>
    </vuln:references>
    <vuln:summary>hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP installation or upgrade by an administrator, related to the product's attempt to correct the ownership of its configuration files within home directories.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:safari"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0123</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.500-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-22T01:46:15.797-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T09:51:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/47917" xml:lang="en">safari-rss-feed-info-disclosure(47917)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021581" xml:lang="en">1021581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33234" xml:lang="en">33234</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33458" xml:lang="en">33458</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isc.sans.org/diary.html?storyid=5689" xml:lang="en">http://isc.sans.org/diary.html?storyid=5689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://brian.mastenbrook.net/display/27" xml:lang="en">http://brian.mastenbrook.net/display/27</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for RSS feeds.  NOTE: as of 20090114, the only disclosure is a vague pre-advisory. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:arrl:tqsllib:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:arrl:tqsllib:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0124</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.530-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-02-06T02:05:51.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T10:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00557.html" xml:lang="en">FEDORA-2009-0543</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=479650" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=479650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33543" xml:lang="en">33543</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2009/01/12/4" xml:lang="en">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511509" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511509</vuln:reference>
    </vuln:references>
    <vuln:summary>The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:finkproject:libnasl:2.2.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:finkproject:libnasl:2.2.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0125</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.547-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-02-10T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T10:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=479655" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=479655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2009-January/002133.html" xml:lang="en">20090120 CVE-2009-0125 (fwd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2009/01/12/4" xml:lang="en">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html" xml:lang="en">SUSE-SR:2009:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.fedoraproject.org/viewvc/rpms/libnasl/F-10/libnasl.spec?r1=1.16&amp;r2=1.17" xml:lang="en">http://cvs.fedoraproject.org/viewvc/rpms/libnasl/F-10/libnasl.spec?r1=1.16&amp;r2=1.17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511517" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511517</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 does not properly check the return value from the OpenSSL DSA_do_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.  NOTE: the upstream vendor has disputed this issue, stating "while we do misuse this function (this is a bug), it has absolutely no security ramification."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:berkeley:boinc_client:6.2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:berkeley:boinc_client:6.4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:berkeley:boinc_client:6.4.5</vuln:product>
      <vuln:product>cpe:/a:berkeley:boinc_client:6.2.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0126</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.563-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-06T01:49:14.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T10:51:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00034.html" xml:lang="en">FEDORA-2009-0578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=479664" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=479664</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33828" xml:lang="en">33828</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33806" xml:lang="en">33806</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2009/01/12/4" xml:lang="en">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html" xml:lang="en">SUSE-SR:2009:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://boinc.berkeley.edu/trac/ticket/823" xml:lang="en">http://boinc.berkeley.edu/trac/ticket/823</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://boinc.berkeley.edu/trac/changeset/16883" xml:lang="en">http://boinc.berkeley.edu/trac/changeset/16883</vuln:reference>
    </vuln:references>
    <vuln:summary>The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:heikkitoivonen:m2crypto:_nil_"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:heikkitoivonen:m2crypto:_nil_</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0127</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.577-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-16T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T11:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=479676" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=479676</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2009/01/12/4" xml:lang="en">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511515" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511515</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED ** M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.  NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0128">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:llnl:slurm:_nil_"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:llnl:slurm:_nil_</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0128</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.610-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-16T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T11:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2009/01/12/4" xml:lang="en">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511511" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511511</vuln:reference>
    </vuln:references>
    <vuln:summary>plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:perl-openssl:libcrypt-openssl-dsa-perl:_nil_"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:perl-openssl:libcrypt-openssl-dsa-perl:_nil_</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0129</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.627-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-16T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T11:33:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2009/01/12/4" xml:lang="en">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511519" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511519</vuln:reference>
    </vuln:references>
    <vuln:summary>libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0130">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:erlang:erlang:_nil_"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:erlang:erlang:_nil_</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0130</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.640-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-16T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T11:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2009/01/12/4" xml:lang="en">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511520" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511520</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED ** lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.  NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus "this report is invalid."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_29::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_30::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_31::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_32::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_33::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_34::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_35::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_55::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_40::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_54::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_41::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_42::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_43::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_44::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_45::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_46::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_48::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_47::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_50::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_49::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_36::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_52::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_37::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_51::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_38::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_53::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_39::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_68::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_67::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_57::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_56::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_66::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_59::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_65::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_74::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_58::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_64::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_73::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_61::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_63::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_60::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_62::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_75::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_71::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_72::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_70::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_69::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_76::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_77::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_78::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_79::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_80::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_81::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_82::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_83::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_84::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_85::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_86::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_87::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_88::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_89::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_90::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_29::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_30::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_31::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_32::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_33::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_34::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_35::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_40::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_41::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_55::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_42::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_43::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_44::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_45::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_46::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_48::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_47::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_50::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_49::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_36::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_52::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_37::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_51::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_54::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_38::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_53::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_39::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_68::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_67::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_57::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_56::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_66::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_59::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_65::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_74::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_58::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_64::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_73::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_61::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_63::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_60::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_62::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_75::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_71::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_72::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_70::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_69::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_76::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_77::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_78::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_79::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_80::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_81::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_82::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_83::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_84::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_85::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_86::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_87::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_88::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_89::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:snv_90::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:opensolaris:snv_48::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_86::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_52::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_76::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_75::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_35::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_49::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_62::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_65::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_87::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_74::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_57::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_66::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_78::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_72::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_45::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_70::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_41::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_46::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_68::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_54::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_42::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_60::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_41::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_74::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_70::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_68::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_79::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_30::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_38::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_51::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_56::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_36::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_33::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_31::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_30::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_56::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_79::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_88::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_40::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_36::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_73::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_88::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_86::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_64::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_57::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_63::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_47::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_32::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_82::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_49::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_53::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_69::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_53::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_65::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_64::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_90::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_78::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_60::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_44::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_80::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_34::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_55::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_32::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_71::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_43::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_83::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_43::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_54::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_34::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_48::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_87::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_66::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_51::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_61::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_84::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_52::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_80::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_44::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_39::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_37::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_29::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_62::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_59::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_63::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_73::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_58::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_85::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_47::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_85::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_69::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_72::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_40::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_50::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_77::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_77::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_71::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_38::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_89::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_55::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_42::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_29::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_61::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_67::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_90::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_81::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_82::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_46::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_59::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_50::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_39::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_37::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_83::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_58::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_81::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_31::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_45::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_76::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_33::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_84::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_35::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_75::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_89::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:snv_67::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0131</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.657-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-02-05T01:53:13.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T13:17:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021600" xml:lang="en">1021600</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33267" xml:lang="en">33267</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239188-1" xml:lang="en">239188</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.opensolaris.org/view_bug.do?bug_id=6711995" xml:lang="en">http://bugs.opensolaris.org/view_bug.do?bug_id=6711995</vuln:reference>
    </vuln:references>
    <vuln:summary>The UFS implementation in the kernel in Sun OpenSolaris snv_29 through snv_90 allows local users to cause a denial of service (panic) via the single posix_fallocate test in the SUSv3 POSIX test suite, related to an F_ALLOCSP fcntl call.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0132">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:opensolaris:::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:8::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:10::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:10::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:9::x86</vuln:product>
      <vuln:product>cpe:/o:sun:opensolaris:::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:8::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0132</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.687-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:56.563-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T14:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33188" xml:lang="en">33188</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-59-1" xml:lang="en">http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-59-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0099" xml:lang="en">ADV-2009-0099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.trapkit.de/advisories/TKADV2009-001.txt" xml:lang="en">http://www.trapkit.de/advisories/TKADV2009-001.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021553" xml:lang="en">1021553</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-247986-1" xml:lang="en">247986</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33516" xml:lang="en">33516</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via a large integer value in the second argument (aka nent argument).</vuln:summary>
  </entry>
  <entry id="CVE-2009-0133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:html_help_workshop:4.74"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:html_help_workshop:4.74</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0133</vuln:cve-id>
    <vuln:published-datetime>2009-01-15T12:30:00.703-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T02:01:03.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T14:07:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/7727" xml:lang="en">7727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4914" xml:lang="en">4914</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:share2:easy_grid_control:3.51"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:share2:easy_grid_control:3.51</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0134</vuln:cve-id>
    <vuln:published-datetime>2009-01-16T13:30:00.203-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-29T02:01:03.767-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-16T16:29:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/47946" xml:lang="en">easygrid-activex-dosavefile-file-overwrite(47946)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33272" xml:lang="en">33272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MILW0RM</vuln:source>
      <vuln:reference href="http://www.milw0rm.com/exploits/7779" xml:lang="en">7779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4913" xml:lang="en">4913</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33537" xml:lang="en">33537</vuln:reference>
    </vuln:references>
    <vuln:summary>Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method.  NOTE: vector 1 could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:amarok:amarok:1.4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:amarok:amarok:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:amarok:amarok:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:amarok:amarok:2.0.1</vuln:product>
      <vuln:product>cpe:/a:amarok:amarok:2.0</vuln:product>
      <vuln:product>cpe:/a:amarok:amarok:1.4.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0135</vuln:cve-id>
    <vuln:published-datetime>2009-01-16T13:30:00.233-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:56.847-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-19T10:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00708.html" xml:lang="en">FEDORA-2009-0715</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=479946" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=479946</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=479560" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=479560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0100" xml:lang="en">ADV-2009-0100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-739-1" xml:lang="en">USN-739-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021558" xml:lang="en">1021558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33210" xml:lang="en">33210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499984/100/0/threaded" xml:lang="en">20090111 [TKADV2009-002] Amarok Integer Overflow and Unchecked Allocation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:030" xml:lang="en">MDVSA-2009:030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1706" xml:lang="en">DSA-1706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://websvn.kde.org/?view=rev&amp;revision=908415" xml:lang="en">http://websvn.kde.org/?view=rev&amp;revision=908415</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://websvn.kde.org/?view=rev&amp;revision=908401" xml:lang="en">http://websvn.kde.org/?view=rev&amp;revision=908401</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://websvn.kde.org/?view=rev&amp;revision=908391" xml:lang="en">http://websvn.kde.org/?view=rev&amp;revision=908391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://trapkit.de/advisories/TKADV2009-002.txt" xml:lang="en">http://trapkit.de/advisories/TKADV2009-002.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4915" xml:lang="en">4915</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200903-34.xml" xml:lang="en">GLSA-200903-34</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34407" xml:lang="en">34407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34315" xml:lang="en">34315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33819" xml:lang="en">33819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33640" xml:lang="en">33640</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33522" xml:lang="en">33522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33505" xml:lang="en">33505</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2009/01/14/2" xml:lang="en">[oss-security] 20090114 CVE Request -- amarok</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html" xml:lang="en">SUSE-SR:2009:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=254896" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=254896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://amarok.kde.org/en/releases/2.0.1.1" xml:lang="en">http://amarok.kde.org/en/releases/2.0.1.1</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple integer overflows in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to execute arbitrary code via an Audible Audio (.aa) file with a large (1) nlen or (2) vlen Tag value, each of which triggers a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:amarok:amarok:1.4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:amarok:amarok:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:amarok:amarok:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:amarok:amarok:2.0.1</vuln:product>
      <vuln:product>cpe:/a:amarok:amarok:2.0</vuln:product>
      <vuln:product>cpe:/a:amarok:amarok:1.4.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0136</vuln:cve-id>
    <vuln:published-datetime>2009-01-16T13:30:00.250-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:56.953-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-01-19T10:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00708.html" xml:lang="en">FEDORA-2009-0715</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=479946" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=479946</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=479560" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=479560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0100" xml:lang="en">ADV-2009-0100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-739-1" xml:lang="en">USN-739-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1021558" xml:lang="en">1021558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33210" xml:lang="en">33210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/499984/100/0/threaded" xml:lang="en">20090111 [TKADV2009-002] Amarok Integer Overflow and Unchecked Allocation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:030" xml:lang="en">MDVSA-2009:030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1706" xml:lang="en">DSA-1706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://websvn.kde.org/?view=rev&amp;revision=908415" xml:lang="en">http://websvn.kde.org/?view=rev&amp;revision=908415</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://websvn.kde.org/?view=rev&amp;revision=908401" xml:lang="en">http://websvn.kde.org/?view=rev&amp;revision=908401</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://websvn.kde.org/?view=rev&amp;revision=908391" xml:lang="en">http://websvn.kde.org/?view=rev&amp;revision=908391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://trapkit.de/advisories/TKADV2009-002.txt" xml:lang="en">http://trapkit.de/advisories/TKADV2009-002.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/4915" xml:lang="en">4915</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200903-34.xml" xml:lang="en">GLSA-200903-34</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34407" xml:lang="en">34407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34315" xml:lang="en">34315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33819" xml:lang="en">33819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33640" xml:lang="en">33640</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33522" xml:lang="en">33522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33505" xml:lang="en">33505</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2009/01/14/2" xml:lang="en">[oss-security] 20090114 CVE Request -- amarok</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html" xml:lang="en">SUSE-SR:2009:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=254896" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=254896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://amarok.kde.org/en/releases/2.0.1.1" xml:lang="en">http://amarok.kde.org/en/releases/2.0.1.1</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple array index errors in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via an Audible Audio (.aa) file with a crafted (1) nlen or (2) vlen Tag value, each of which can lead to an invalid pointer dereference, or the writing of a 0x00 byte to an arbitrary memory location, after an allocation failure.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:safari"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0137</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:05.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-08-19T01:25:07.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T10:19:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00001.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Safari RSS in Apple Mac OS X 10.4.11 and 10.5.6, and Windows XP and Vista, allow remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed: URL, related to "input validation issues."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0138</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:05.017-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:57.157-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T10:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33813" xml:lang="en">33813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:summary>servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify the system configuration.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0139</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:05.030-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:57.237-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T10:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a denial of service (system shutdown) or execute arbitrary code via a crafted SMB file system that triggers a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0140">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0140</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:05.047-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:57.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T10:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0141</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T19:30:05.077-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:57.437-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T10:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/48727" xml:lang="en">macosx-xterm-information-disclosure(48727)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/alerts/2009/Feb/1021729.html" xml:lang="en">1021729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:summary>XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0142</vuln:cve-id>
    <vuln:published-datetime>2009-02-12T18:30:01.110-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T22:17:57.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-02-13T08:23:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0422" xml:lang="en">ADV-2009-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33812" xml:lang="en">33812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33759" xml:lang="en">33759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/33937" xml:lang="en">33937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in AFP Server in Apple Mac OS X 10.5.6 allows local users to cause a denial of service (infinite loop) via unspecified vectors related to "file enumeration logic."</vuln:summary>
  </entry>
  <entry id="CVE-2009-0143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4.2::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:3.0.1::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:3.0::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.72::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1.30::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:1.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:1.0:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:1.1.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:1.1.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:1.1.2:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:1.1.2:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0.1:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0.1:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0.2:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0.2:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0.3:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0.3:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0.4:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0.4:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0:-:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:2.0:-:mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:2.0.4:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:3.0::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.4:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:1.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.4::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0.3:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0.4:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:1.1.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0.3:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:1.1.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:1.1.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:1.1.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.4:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.4.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1.30::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.72::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:1.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:3.0.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:2.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1::windows</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1:-:mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0143</vuln:cve-id>
    <vuln:published-datetime>2009-03-14T14:30:00.437-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:29:48.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-03-15T09:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5336" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5336" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3487" xml:lang="en">http://support.apple.com/kb/HT3487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce//2009/Mar/msg00001.html" xml:lang="en">APPLE-SA-2009-03-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/49201" xml:lang="en">itunes-podcast-information-disclosure(49201)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0702" xml:lang="en">ADV-2009-0702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34094" xml:lang="en">34094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1021843" xml:lang="en">1021843</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34254" xml:lang="en">34254</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/52579" xml:lang="en">52579</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5336" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5336" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0144">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0144</vuln:cve-id>
    <vuln:published-datetime>2009-05-13T11:30:00.250-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-05-16T01:28:55.703-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-05-14T09:50:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" xml:lang="en">TA09-133A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3549" xml:lang="en">http://support.apple.com/kb/HT3549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" xml:lang="en">APPLE-SA-2009-05-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/50479" xml:lang="en">macos-cfnetwork-info-disclosure(50479)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1297" xml:lang="en">ADV-2009-1297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022214" xml:lang="en">1022214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34926" xml:lang="en">34926</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35074" xml:lang="en">35074</vuln:reference>
    </vuln:references>
    <vuln:summary>CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie headers, which allows remote attackers to obtain sensitive information by sniffing the network for "secure cookies" that are sent over unencrypted HTTP connections.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0145</vuln:cve-id>
    <vuln:published-datetime>2009-05-13T11:30:00.280-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-06-23T01:30:42.437-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-05-14T10:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" xml:lang="en">TA09-133A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3549" xml:lang="en">http://support.apple.com/kb/HT3549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" xml:lang="en">APPLE-SA-2009-05-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/50481" xml:lang="en">macos-coregraphics-pdf-code-execution(50481)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1621" xml:lang="en">ADV-2009-1621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1522" xml:lang="en">ADV-2009-1522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1297" xml:lang="en">ADV-2009-1297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022209" xml:lang="en">1022209</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34926" xml:lang="en">34926</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3639" xml:lang="en">http://support.apple.com/kb/HT3639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3613" xml:lang="en">http://support.apple.com/kb/HT3613</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35379" xml:lang="en">35379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35074" xml:lang="en">35074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" xml:lang="en">APPLE-SA-2009-06-17-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" xml:lang="en">APPLE-SA-2009-06-08-1</vuln:reference>
    </vuln:references>
    <vuln:summary>CoreGraphics in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0146">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:3.02"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:3.00"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:3.01"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:2.03"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:2.02"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:2.01"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:2.00"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:1.01"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:1.00a"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:1.00"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.93c"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.93b"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.93a"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.93"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.92e"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.92d"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.92c"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.92b"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.92a"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.92"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.91c"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.91b"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.91a"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.91"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.90"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.80"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.5a"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.5-1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.5-2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.6-1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.9-1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.10-1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.6-3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.6-2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.21:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.21:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.23:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.22:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.22:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:cups:1.3.9</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.8</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:3.02</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.91c</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:2.01</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.11</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.16</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.14</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc3</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:2.00</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.22</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.5a</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.92c</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.13</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.10</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.9</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.6-2</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.6</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.92a</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:1.00</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.7</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.8</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.9</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.92b</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.90</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:1.00a</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.22:rc2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.21:rc1</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:2.03</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.10-1</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:3.01</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.7</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.91</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.6-3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc6</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.93c</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.2</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:2.02</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.10</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.5-1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.8</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.91b</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.92e</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.7a</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.9-1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.6</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.23:rc1</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.92</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.6-1</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.91a</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.6</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.4</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:3.00</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.93</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.12</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:1.01</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.21:rc2</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.11</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.2</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.93b</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.2</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.7</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.22:rc1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.5-2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.21</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.3</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.80</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.18</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.7</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.23</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.92d</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.6</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.15</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.93a</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.17</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.11</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-0146</vuln:cve-id>
    <vuln:published-datetime>2009-04-23T13:30:01.547-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-12-21T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2009-04-23T14:13:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9632" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9632" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" xml:lang="en">TA09-133A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0430.html" xml:lang="en">RHSA-2009:0430</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" xml:lang="en">FEDORA-2009-6982</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" xml:lang="en">FEDORA-2009-6973</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" xml:lang="en">FEDORA-2009-6972</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=490612" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=490612</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1040" xml:lang="en">ADV-2010-1040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1621" xml:lang="en">ADV-2009-1621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1297" xml:lang="en">ADV-2009-1297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1077" xml:lang="en">ADV-2009-1077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1066" xml:lang="en">ADV-2009-1066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/1065" xml:lang="en">ADV-2009-1065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1022073" xml:lang="en">1022073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/34568" xml:lang="en">34568</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/502761/100/0/threaded" xml:lang="en">20090417 rPSA-2009-0059-1 poppler</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/502750/100/0/threaded" xml:lang="en">20090417 rPSA-2009-0061-1 cups</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0480.html" xml:lang="en">RHSA-2009:0480</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0431.html" xml:lang="en">RHSA-2009:0431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2009-0429.html" xml:lang="en">RHSA-2009:0429</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" xml:lang="en">MDVSA-2010:087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" xml:lang="en">MDVSA-2009:101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1793" xml:lang="en">DSA-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2009/dsa-1790" xml:lang="en">DSA-1790</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2009-0061" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2009-0061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2009-0059" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2009-0059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3639" xml:lang="en">http://support.apple.com/kb/HT3639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3549" xml:lang="en">http://support.apple.com/kb/HT3549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" xml:lang="en">SSA:2009-129-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200904-20.xml" xml:lang="en">GLSA-200904-20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35685" xml:lang="en">35685</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35618" xml:lang="en">35618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35074" xml:lang="en">35074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35065" xml:lang="en">35065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35064" xml:lang="en">35064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35037" xml:lang="en">35037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34991" xml:lang="en">34991</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34963" xml:lang="en">34963</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34959" xml:lang="en">34959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34852" xml:lang="en">34852</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34756" xml:lang="en">34756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34755" xml:lang="en">34755</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34481" xml:lang="en">34481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/34291" xml:lang="en">34291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2009-0458.html" xml:lang="en">RHSA-2009:0458</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" xml:lang="en">SUSE-SR:2009:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" xml:lang="en">SUSE-SR:2009:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" xml:lang="en">SUSE-SA:2009:024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" xml:lang="en">APPLE-SA-2009-05-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" xml:lang="en">APPLE-SA-2009-06-17-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=263028" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=263028</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9632" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9632" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.</vuln:summary>
  </entry>
  <entry id="CVE-2009-0147">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:3.02"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:3.00"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:3.01"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:2.03"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:2.02"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:2.01"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:2.00"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:1.01"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:1.00a"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:1.00"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.93c"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.93b"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.93a"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.93"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.92e"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.92d"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.92c"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.92b"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.92a"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.92"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.91c"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.91b"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.91a"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.91"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.90"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.80"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.5a"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:foolabs:xpdf:0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.5-1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.5-2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.6-1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.9-1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.10-1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.6-3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.6-2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.19:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.21:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.20:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.21:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.23:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.22:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.22:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:cups:1.1.23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:cups:1.3.9</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.8</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:3.02</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.91c</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:2.01</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.11</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.16</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.14</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc3</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:2.00</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.22</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.5a</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.92c</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.13</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.10</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.9</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.6-2</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.6</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.92a</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:1.00</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.7</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.8</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.9</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.92b</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.90</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:1.00a</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.22:rc2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.21:rc1</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:2.03</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.10-1</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:3.01</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.7</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.91</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.6-3</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc6</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.93c</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.2</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:2.02</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.10</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.5-1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.8</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.91b</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.92e</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.7a</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.9-1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.6</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.23:rc1</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.92</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.6-1</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.91a</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.6</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.4</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:3.00</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.93</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.12</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:1.01</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.21:rc2</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.11</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.2</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.93b</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.2</vuln:product>
      <vuln:product>cpe:/a:foolabs:xpdf:0.7</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.2.4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.22:rc1</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc4</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.19:rc5</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.5-2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.1.20:rc2</vuln:product>
      <vuln:product>cpe:/a:apple:cups:1.3.5</vuln