<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" nvd_xml_version="2.0" pub_date="2013-05-17T04:24:41" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
  <entry id="CVE-2010-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:gzip:1.2.4a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:gzip:1.3.13</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3.1</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3.12</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3.8</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3.4</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3.3</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3.7</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3.5</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3.9</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.2.4</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3.2</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.2.4a</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3.11</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3.6</vuln:product>
      <vuln:product>cpe:/a:gnu:gzip:1.3.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0001</vuln:cve-id>
    <vuln:published-datetime>2010-01-29T13:30:00.947-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-25T22:45:05.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-31T20:09:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7511" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7511" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10546" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10546" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2010-0095.html" xml:lang="en">RHSA-2010:0095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=554418" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=554418</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1872" xml:lang="en">ADV-2010-1872</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1796" xml:lang="en">ADV-2010-1796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0185" xml:lang="en">ADV-2010-0185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-889-1" xml:lang="en">USN-889-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0061.html" xml:lang="en">RHSA-2010:0061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/61869" xml:lang="en">61869</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:152" xml:lang="en">MDVSA-2011:152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:020" xml:lang="en">MDVSA-2010:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:019" xml:lang="en">MDVSA-2010:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2010/dsa-2074" xml:lang="en">DSA-2074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2010/dsa-1974" xml:lang="en">DSA-1974</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4435" xml:lang="en">http://support.apple.com/kb/HT4435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1023490" xml:lang="en">1023490</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40689" xml:lang="en">40689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40655" xml:lang="en">40655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40551" xml:lang="en">40551</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38232" xml:lang="en">38232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38225" xml:lang="en">38225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38223" xml:lang="en">38223</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38220" xml:lang="en">38220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://savannah.gnu.org/forum/forum.php?forum_id=6153" xml:lang="en">http://savannah.gnu.org/forum/forum.php?forum_id=6153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ncompress.sourceforge.net/#status" xml:lang="en">http://ncompress.sourceforge.net/#status</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html" xml:lang="en">SUSE-SA:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" xml:lang="en">APPLE-SA-2010-11-10-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083" xml:lang="en">HPSBMA02554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083" xml:lang="en">HPSBMA02554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.savannah.gnu.org/cgit/gzip.git/commit/?id=a3db5806d012082b9e25cc36d09f19cd736a468f" xml:lang="en">http://git.savannah.gnu.org/cgit/gzip.git/commit/?id=a3db5806d012082b9e25cc36d09f19cd736a468f</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7511" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7511" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10546" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10546" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:bash:2.05:b"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:bash:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:bash:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:bash:3.2.48"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:bash:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:bash:3.2</vuln:product>
      <vuln:product>cpe:/a:gnu:bash:4.0</vuln:product>
      <vuln:product>cpe:/a:gnu:bash:2.05:b</vuln:product>
      <vuln:product>cpe:/a:gnu:bash:3.0</vuln:product>
      <vuln:product>cpe:/a:gnu:bash:3.2.48</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0002</vuln:cve-id>
    <vuln:published-datetime>2010-01-14T13:30:00.467-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-08T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-15T09:31:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:004" xml:lang="en">MDVSA-2010:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://qa.mandriva.com/show_bug.cgi?id=56882" xml:lang="en">https://qa.mandriva.com/show_bug.cgi?id=56882</vuln:reference>
    </vuln:references>
    <vuln:summary>The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows local users to send escape sequences to terminal emulators, or hide the existence of a file, via a crafted filename.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.12::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.11::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.8::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.7::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.6::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.5::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.4::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.3::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.2::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.10::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.9::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29:rc8-kk"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29:git1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29.rc2-git1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:linux:kernel:2.6.24.7"/>
        <cpe-lang:fact-ref name="cpe:/a:linux:kernel:2.6.25.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.30:rc7-git6"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.4.27"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.4.35"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.0.33"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:6.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:6.2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:6.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:6.0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:6.0.54"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.6.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.2.52"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.2.30.1"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.2.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.30:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.30:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.30:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29:rc2_git7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29.rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:git-6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.10</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.1.9</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.3.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.30:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29.rc1</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:6.3.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.11</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:6.0.60</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.13</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.3.20</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:6.0.54</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.5::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.6::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.19</vuln:product>
      <vuln:product>cpe:/a:linux:kernel:2.6.25.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29.rc2-git1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.9::x86_64</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.3.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.6</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:6.2.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.30:rc7-git6</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.4.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.3::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.5</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:6.1.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.7::x86_64</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.2.52</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.30:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.2::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.10::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc6</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.2.30.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.20</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.2.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.16</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.8::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.1</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.2.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.11::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.13</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29:rc8-kk</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.12::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29:rc2_git7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.4::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.27</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.4.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:git-6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23_rc1</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.6.10.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.4</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.7.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29:git1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.16</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.0.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.14</vuln:product>
      <vuln:product>cpe:/a:linux:kernel:2.6.24.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.1::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.7</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.2.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.30:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.5.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.9</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.0.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0003</vuln:cve-id>
    <vuln:published-datetime>2010-01-26T13:30:01.010-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-27T07:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10550" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10550" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2010-0146.html" xml:lang="en">RHSA-2010:0146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=554578" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=554578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/37724" xml:lang="en">37724</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0161.html" xml:lang="en">RHSA-2010:0161</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0147.html" xml:lang="en">RHSA-2010:0147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/13/4" xml:lang="en">[oss-security] 20100113 Re: CVE request - kernel: infoleak if print-fatal-signals=1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/12/1" xml:lang="en">[oss-security] 20100112 CVE request - kernel: infoleak if print-fatal-signals=1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.4" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2010/dsa-2005" xml:lang="en">DSA-2005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2010/dsa-1996" xml:lang="en">DSA-1996</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43315" xml:lang="en">43315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39033" xml:lang="en">39033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38779" xml:lang="en">38779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38492" xml:lang="en">38492</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38333" xml:lang="en">38333</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://patchwork.kernel.org/patch/69752/" xml:lang="en">http://patchwork.kernel.org/patch/69752/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" xml:lang="en">SUSE-SA:2010:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" xml:lang="en">SUSE-SA:2010:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" xml:lang="en">SUSE-SA:2010:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034250.html" xml:lang="en">FEDORA-2010-0919</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b45c6e76bc2c72f6426c14bed64fdcbc9bf37cb0" xml:lang="en">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b45c6e76bc2c72f6426c14bed64fdcbc9bf37cb0</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10550" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10550" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations by jumping to an address and then reading a log file, and might allow local users to cause a denial of service (system slowdown or crash) by jumping to an address.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.1</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.4</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.7</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.1.1</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.3</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.5</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.2</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.6</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.1.0</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.8</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0004</vuln:cve-id>
    <vuln:published-datetime>2010-01-29T13:30:00.997-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-02-02T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-01T09:07:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01464.html" xml:lang="en">FEDORA-2009-13634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01421.html" xml:lang="en">FEDORA-2009-13610</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/14/4" xml:lang="en">[oss-security] 20100114 Re: CVE Request: viewvc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/13/5" xml:lang="en">[oss-security] 20100113 Re: CVE Request: viewvc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/11/2" xml:lang="en">[oss-security] 20100111 CVE Request: viewvc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://viewvc.tigris.org/source/browse/viewvc?view=rev&amp;revision=2300" xml:lang="en">http://viewvc.tigris.org/source/browse/viewvc?view=rev&amp;revision=2300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?r1=2242&amp;r2=2313&amp;pathrev=HEAD" xml:lang="en">http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?r1=2242&amp;r2=2313&amp;pathrev=HEAD</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://viewvc.tigris.org/source/browse/%2Acheckout%2A/viewvc/trunk/docs/release-notes/1.1.0.html?revision=2222" xml:lang="en">http://viewvc.tigris.org/source/browse/*checkout*/viewvc/trunk/docs/release-notes/1.1.0.html?revision=2222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html" xml:lang="en">SUSE-SA:2010:008</vuln:reference>
    </vuln:references>
    <vuln:summary>ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:viewvc:viewvc:1.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.1</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.4</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.7</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.1.1</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.3</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.5</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.2</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.6</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.1.0</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.0.8</vuln:product>
      <vuln:product>cpe:/a:viewvc:viewvc:1.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0005</vuln:cve-id>
    <vuln:published-datetime>2010-01-29T13:30:01.057-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-02-02T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-01T09:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?r1=2242&amp;r2=2313&amp;pathrev=HEAD" xml:lang="en">http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?r1=2242&amp;r2=2313&amp;pathrev=HEAD</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01464.html" xml:lang="en">FEDORA-2009-13634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01421.html" xml:lang="en">FEDORA-2009-13610</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/13/5" xml:lang="en">[oss-security] 20100113 Re: CVE Request: viewvc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/11/2" xml:lang="en">[oss-security] 20100111 CVE Request: viewvc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://viewvc.tigris.org/source/browse/viewvc?view=rev&amp;revision=2300" xml:lang="en">http://viewvc.tigris.org/source/browse/viewvc?view=rev&amp;revision=2300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html" xml:lang="en">SUSE-SA:2010:008</vuln:reference>
    </vuln:references>
    <vuln:summary>query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24_rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.36.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.12::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.11::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.8::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.7::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.6::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.5::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.4::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.3::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.2::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.10::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.1::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.9::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.26.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29:rc8-kk"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29:git1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29.rc2-git1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:linux:kernel:2.6.24.7"/>
        <cpe-lang:fact-ref name="cpe:/a:linux:kernel:2.6.25.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.25.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.30:rc7-git6"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.4.27"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.4.35"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:7.0.33"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:6.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:6.2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:6.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:6.0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:6.0.54"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.6.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.2.52"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.2.30.1"/>
        <cpe-lang:fact-ref name="cpe:/a:intel:e1000:5.2.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.30:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.30:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.30:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29:rc2_git7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29.rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.29:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:git-6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.10</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.1.9</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.3.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.30:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29.rc1</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:6.3.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.11</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:6.0.60</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.13</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.3.20</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:6.0.54</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.5::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.6::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.19</vuln:product>
      <vuln:product>cpe:/a:linux:kernel:2.6.25.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29.rc2-git1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.9::x86_64</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.3.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.6</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:6.2.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.30:rc7-git6</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.4.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.3::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.5</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:6.1.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.7::x86_64</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.2.52</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.30:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.2::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.10::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc6</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.2.30.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.20</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.2.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.16</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.8::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.1</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.2.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.11::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.13</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29:rc8-kk</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.12::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29:rc2_git7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.4::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.27</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.4.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:git-6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23_rc1</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.6.10.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.4</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.7.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29:git1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.16</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.0.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.14</vuln:product>
      <vuln:product>cpe:/a:linux:kernel:2.6.24.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24_rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.1::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.7</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.2.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.30:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.36</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:5.5.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.29:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.25.9</vuln:product>
      <vuln:product>cpe:/a:intel:e1000:7.0.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.26.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0006</vuln:cve-id>
    <vuln:published-datetime>2010-01-26T13:30:01.057-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-27T09:19:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=555217" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=555217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/37810" xml:lang="en">37810</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/61876" xml:lang="en">61876</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/14/2" xml:lang="en">[oss-security] 20100114 CVE-2010-0006 - kernel: ipv6: skb_dst() can be NULL in ipv6_hop_jumbo()</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.4" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://security-tracker.debian.org/tracker/CVE-2010-0006" xml:lang="en">http://security-tracker.debian.org/tracker/CVE-2010-0006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38333" xml:lang="en">38333</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38168" xml:lang="en">38168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=linux-netdev&amp;m=126343325807340&amp;w=2" xml:lang="en">[linux-netdev] 20100114 [PATCH]: ipv6: skb_dst() can be NULL in ipv6_hop_jumbo().</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" xml:lang="en">SUSE-SA:2010:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034250.html" xml:lang="en">FEDORA-2010-0919</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2570a4f5428bcdb1077622342181755741e7fa60" xml:lang="en">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2570a4f5428bcdb1077622342181755741e7fa60</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://cert.fi/en/reports/2010/vulnerability341748.html" xml:lang="en">http://cert.fi/en/reports/2010/vulnerability341748.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=300951" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=300951</vuln:reference>
    </vuln:references>
    <vuln:summary>The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid IPv6 jumbogram, a related issue to CVE-2007-4567.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.24:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.33:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.33:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.33:rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.33:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.24:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.33:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.33:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.32.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0007</vuln:cve-id>
    <vuln:published-datetime>2010-01-19T11:30:01.057-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-20T11:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9630" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9630" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0109" xml:lang="en">ADV-2010-0109</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2010-0146.html" xml:lang="en">RHSA-2010:0146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=555238" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=555238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/55602" xml:lang="en">kernel-ebtables-security-bypass(55602)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/37762" xml:lang="en">37762</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0161.html" xml:lang="en">RHSA-2010:0161</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0147.html" xml:lang="en">RHSA-2010:0147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/14/3" xml:lang="en">[oss-security] 20100114 Re: CVE Request: kernel ebtables perm check</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/14/1" xml:lang="en">[oss-security] 20100113 CVE Request: kernel ebtables perm check</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:051" xml:lang="en">MDVSA-2011:051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc4" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2010/dsa-2005" xml:lang="en">DSA-2005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2010/dsa-1996" xml:lang="en">DSA-1996</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43315" xml:lang="en">43315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39033" xml:lang="en">39033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38779" xml:lang="en">38779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38492" xml:lang="en">38492</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38333" xml:lang="en">38333</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38296" xml:lang="en">38296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38133" xml:lang="en">38133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" xml:lang="en">SUSE-SA:2010:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html" xml:lang="en">SUSE-SA:2010:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" xml:lang="en">SUSE-SA:2010:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" xml:lang="en">SUSE-SA:2010:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00008.html" xml:lang="en">SUSE-SA:2010:007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034250.html" xml:lang="en">FEDORA-2010-0919</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=dce766af541f6605fa9889892c0280bab31c66ab" xml:lang="en">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=dce766af541f6605fa9889892c0280bab31c66ab</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9630" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9630" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.48"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.47"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.46"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.45"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.52"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.51"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.50"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.49"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.57"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.56"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.55"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.54"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.53"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.61"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.62"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.60"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.59"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.58"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.22.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.52</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.47</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.53</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.61</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.62</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.46</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.50</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.54</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.42</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.56</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.55</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.44</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.59</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.51</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.57</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.58</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.45</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.49</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.43</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.22.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.48</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.60</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0008</vuln:cve-id>
    <vuln:published-datetime>2010-03-19T15:30:00.360-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-22T15:44:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11160" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11160" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/03/17/2" xml:lang="en">[oss-security] 20100317 CVE-2010-0008 kernel: sctp remote denial of service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ece25dfa0991f65c4e1d26beb1c3c45bda4239b8" xml:lang="en">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ece25dfa0991f65c4e1d26beb1c3c45bda4239b8</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2010-0146.html" xml:lang="en">RHSA-2010:0146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=555658" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=555658</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0342.html" xml:lang="en">RHSA-2010:0342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0147.html" xml:lang="en">RHSA-2010:0147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43315" xml:lang="en">43315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39295" xml:lang="en">39295</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11160" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11160" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:couchdb:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:couchdb:0.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:couchdb:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:couchdb:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:couchdb:0.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:couchdb:0.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:couchdb:0.8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:couchdb:0.9.0</vuln:product>
      <vuln:product>cpe:/a:apache:couchdb:0.8.0</vuln:product>
      <vuln:product>cpe:/a:apache:couchdb:0.9.1</vuln:product>
      <vuln:product>cpe:/a:apache:couchdb:0.9.2</vuln:product>
      <vuln:product>cpe:/a:apache:couchdb:0.8.1</vuln:product>
      <vuln:product>cpe:/a:apache:couchdb:0.10.0</vuln:product>
      <vuln:product>cpe:/a:apache:couchdb:0.10.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0009</vuln:cve-id>
    <vuln:published-datetime>2010-04-05T12:30:00.547-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-06-07T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-06T15:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://couchdb.apache.org/security.html" xml:lang="en">http://couchdb.apache.org/security.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=578572" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=578572</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/39116" xml:lang="en">39116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/510427/100/0/threaded" xml:lang="en">20100331 [SECURITY] CVE-2008-2370: Apache CouchDB Timing Attack Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/63350" xml:lang="en">63350</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39146" xml:lang="en">39146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2010-03/0267.html" xml:lang="en">20100331 [SECURITY] CVE-2008-2370: Apache CouchDB Timing Attack Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.39"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.40"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.41"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.38"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.37"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.36"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.35"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.34"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.33"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.32"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.31"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.30"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.29"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.27"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.26"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.24"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.23"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:0.8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:0.8.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:1.3.31</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.2.4</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.10</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.33</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.15</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.11</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.19</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.41</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.2</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:0.8.11</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.30</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.34</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.24</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.28</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.2.5</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.13</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.12</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.26</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.27</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.2</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.14</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.1</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.29</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.35</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.4</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.32</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.17</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.18</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.36</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.2.6</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.22</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0.3</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.20</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.38</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.40</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.37</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.25</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.3</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.39</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0.5</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.1</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:0.8.14</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.3.23</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0010</vuln:cve-id>
    <vuln:published-datetime>2010-02-02T11:30:02.437-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-06T23:05:17.817-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-03T10:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7923" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7923" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/55941" xml:lang="en">modproxy-approxysendfb-bo(55941)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1001" xml:lang="en">ADV-2010-1001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0240" xml:lang="en">ADV-2010-0240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023533" xml:lang="en">1023533</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/37966" xml:lang="en">37966</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/509185/100/0/threaded" xml:lang="en">20100127 Mod_proxy from apache 1.3 - Integer overflow which causes heap overflow.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://site.pi3.com.pl/adv/mod_proxy.txt" xml:lang="en">http://site.pi3.com.pl/adv/mod_proxy.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39656" xml:lang="en">39656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38319" xml:lang="en">38319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.org/1001-exploits/modproxy-overflow.txt" xml:lang="en">http://packetstormsecurity.org/1001-exploits/modproxy-overflow.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" xml:lang="en">SSRT090208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" xml:lang="en">HPSBOV02683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html" xml:lang="en">SUSE-SR:2010:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://httpd.apache.org/dev/dist/CHANGES_1.3.42" xml:lang="en">http://httpd.apache.org/dev/dist/CHANGES_1.3.42</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blog.pi3.com.pl/?p=69" xml:lang="en">http://blog.pi3.com.pl/?p=69</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0589.html" xml:lang="en">20100127 Mod_proxy from apache 1.3 - Integer overflow which causes heap overflow.</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7923" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7923" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:uzbl:uzbl:2009.12.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:uzbl:uzbl:2009.12.22</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0011</vuln:cve-id>
    <vuln:published-datetime>2010-02-25T14:30:00.437-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-04-28T01:44:55.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-26T12:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://github.com/Dieterbe/uzbl/downloads" xml:lang="en">http://github.com/Dieterbe/uzbl/downloads</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/56612" xml:lang="en">uzbl-evaljs-command-execution(56612)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.uzbl.org/news.php?id=22" xml:lang="en">http://www.uzbl.org/news.php?id=22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/06/3" xml:lang="en">[oss-security] 20100106 Re: CVE request - uzbl remote code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/06/1" xml:lang="en">[oss-security] 20100106 CVE request - uzbl remote code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.uzbl.org/pipermail/uzbl-dev-uzbl.org/2010-January/000586.html" xml:lang="en">[uzbl-dev] 20100102 Fw: Uzbl: security issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://github.com/Dieterbe/uzbl/commit/1958b52d41cba96956dc1995660de49525ed1047" xml:lang="en">http://github.com/Dieterbe/uzbl/commit/1958b52d41cba96956dc1995660de49525ed1047</vuln:reference>
    </vuln:references>
    <vuln:summary>The eval_js function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to execute arbitrary commands via JavaScript code.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:transmissionbt:transmission:1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:transmissionbt:transmission:1.34"/>
        <cpe-lang:fact-ref name="cpe:/a:transmissionbt:transmission:1.75"/>
        <cpe-lang:fact-ref name="cpe:/a:transmissionbt:transmission:1.76"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:transmissionbt:transmission:1.75</vuln:product>
      <vuln:product>cpe:/a:transmissionbt:transmission:1.34</vuln:product>
      <vuln:product>cpe:/a:transmissionbt:transmission:1.22</vuln:product>
      <vuln:product>cpe:/a:transmissionbt:transmission:1.76</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0012</vuln:cve-id>
    <vuln:published-datetime>2010-01-08T12:30:02.317-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-26T01:36:34.233-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-11T07:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://launchpad.net/bugs/500625" xml:lang="en">https://launchpad.net/bugs/500625</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/55454" xml:lang="en">transmission-name-directory-traversal(55454)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0071" xml:lang="en">ADV-2010-0071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/06/4" xml:lang="en">[oss-security] 20100106 Re: CVE Request: Transmission</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/06/2" xml:lang="en">[oss-security] 20100106 CVE Request: Transmission</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.mail-archive.com/debian-devel-changes@lists.debian.org/msg264483.html" xml:lang="en">[debian-devel-changes] 20100105 Accepted transmission 1.77-1 (source all amd64)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2010/dsa-1967" xml:lang="en">DSA-1967</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://trac.transmissionbt.com/wiki/Changes#version-1.77" xml:lang="en">http://trac.transmissionbt.com/wiki/Changes#version-1.77</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://trac.transmissionbt.com/changeset/9829/" xml:lang="en">http://trac.transmissionbt.com/changeset/9829/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://security.debian.org/pool/updates/main/t/transmission/transmission_1.22-1+lenny2.diff.gz" xml:lang="en">http://security.debian.org/pool/updates/main/t/transmission/transmission_1.22-1+lenny2.diff.gz</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38005" xml:lang="en">38005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/37993" xml:lang="en">37993</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html" xml:lang="en">SUSE-SA:2010:008</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adium:adium:1.3.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adium:adium:1.3.8</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0013</vuln:cve-id>
    <vuln:published-datetime>2010-01-09T13:30:01.697-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-01-04T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-11T09:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10333" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10333" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=552483" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=552483</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1020" xml:lang="en">ADV-2010-1020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/3663" xml:lang="en">ADV-2009-3663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/3662" xml:lang="en">ADV-2009-3662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/07/2" xml:lang="en">[oss-security] 20100107 Re: CVE request - pidgin MSN arbitrary file upload</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/07/1" xml:lang="en">[oss-security] 20100107 Re: CVE request - pidgin MSN arbitrary file upload</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/02/1" xml:lang="en">[oss-security] 20100102 CVE request - pidgin MSN arbitrary file upload</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:085" xml:lang="en">MDVSA-2010:085</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022203.1-1" xml:lang="en">1022203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-277450-1" xml:lang="en">277450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38915" xml:lang="en">38915</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/37961" xml:lang="en">37961</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/37954" xml:lang="en">37954</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/37953" xml:lang="en">37953</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html" xml:lang="en">SUSE-SR:2010:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/033848.html" xml:lang="en">FEDORA-2010-0429</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/033771.html" xml:lang="en">FEDORA-2010-0368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html" xml:lang="en">http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.pidgin.im/viewmtn/revision/diff/3d02401cf232459fc80c0837d31e05fae7ae5467/with/c64a1adc8bda2b4aeaae1f273541afbc4f71b810/libpurple/protocols/msn/slp.c" xml:lang="en">http://developer.pidgin.im/viewmtn/revision/diff/3d02401cf232459fc80c0837d31e05fae7ae5467/with/c64a1adc8bda2b4aeaae1f273541afbc4f71b810/libpurple/protocols/msn/slp.c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://d.pidgin.im/viewmtn/revision/info/c64a1adc8bda2b4aeaae1f273541afbc4f71b810" xml:lang="en">http://d.pidgin.im/viewmtn/revision/info/c64a1adc8bda2b4aeaae1f273541afbc4f71b810</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://d.pidgin.im/viewmtn/revision/info/4be2df4f72bd8a55cdae7f2554b73342a497c92f" xml:lang="en">http://d.pidgin.im/viewmtn/revision/info/4be2df4f72bd8a55cdae7f2554b73342a497c92f</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://d.pidgin.im/viewmtn/revision/info/3d02401cf232459fc80c0837d31e05fae7ae5467" xml:lang="en">http://d.pidgin.im/viewmtn/revision/info/3d02401cf232459fc80c0837d31e05fae7ae5467</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10333" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10333" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122.  NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.99.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.99.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.6.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.3.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.3.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.4.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.6.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.99.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.3.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.2.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.99.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.7.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.7.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.5.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.4.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0014</vuln:cve-id>
    <vuln:published-datetime>2010-01-14T13:30:00.513-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-01-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-15T09:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://fedorahosted.org/sssd/wiki/Releases/Notes-1.0.1" xml:lang="en">https://fedorahosted.org/sssd/wiki/Releases/Notes-1.0.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=553233" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=553233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/37747" xml:lang="en">37747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38160" xml:lang="en">38160</vuln:reference>
    </vuln:references>
    <vuln:summary>System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary password, to the screen-locking program on a workstation that has any user's Kerberos ticket-granting ticket (TGT); and might allow remote attackers to bypass intended access restrictions via vectors involving an arbitrary password in conjunction with a valid TGT.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.10.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:glibc:2.10.2</vuln:product>
      <vuln:product>cpe:/a:gnu:glibc:2.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0015</vuln:cve-id>
    <vuln:published-datetime>2010-01-14T13:30:00.577-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-06-17T01:37:14.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-15T09:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/11/6" xml:lang="en">[oss-security] 20100111 Re: CVE id request: GNU libc: NIS shadow password leakage</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/08/2" xml:lang="en">[oss-security] 20100109 Re: CVE id request: GNU libc: NIS shadow password leakage</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/08/1" xml:lang="en">[oss-security] 20100108 Re: CVE id request: GNU libc: NIS shadow password leakage</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/07/3" xml:lang="en">[oss-security] 20100107 CVE id request: GNU libc: NIS shadow password leakage</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:112" xml:lang="en">MDVSA-2010:112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:111" xml:lang="en">MDVSA-2010:111</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.debian.org/viewsvn/pkg-glibc/glibc-package/trunk/debian/patches/any/submitted-nis-shadow.diff?revision=4062&amp;view=markup" xml:lang="en">http://svn.debian.org/viewsvn/pkg-glibc/glibc-package/trunk/debian/patches/any/submitted-nis-shadow.diff?revision=4062&amp;view=markup</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://sourceware.org/bugzilla/show_bug.cgi?id=11134" xml:lang="en">http://sourceware.org/bugzilla/show_bug.cgi?id=11134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=oss-security&amp;m=126320570505651&amp;w=2" xml:lang="en">[oss-security] 20100111 Re: CVE id request: GNU libc: NIS shadow password leakage</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=oss-security&amp;m=126320356003425&amp;w=2" xml:lang="en">[oss-security] 20100111 Re: CVE id request: GNU libc: NIS shadow password leakage</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560333" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560333</vuln:reference>
    </vuln:references>
    <vuln:summary>nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:-:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp3:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp3:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:professional_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000:-:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0016</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:00.877-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:44.480-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T11:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8278" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8278" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-006.mspx" xml:lang="en">MS10-006</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8278" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8278" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The SMB client implementation in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate response fields, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted response, aka "SMB Client Pool Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:r2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:-:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0017</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:00.923-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:44.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T11:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8298" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8298" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-006.mspx" xml:lang="en">MS10-006</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8298" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8298" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0018</vuln:cve-id>
    <vuln:published-datetime>2010-01-13T14:30:00.640-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-14T08:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8324" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8324" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012B.html" xml:lang="en">TA10-012B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-001.mspx" xml:lang="en">MS10-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0095" xml:lang="en">ADV-2010-0095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023432" xml:lang="en">1023432</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/37671" xml:lang="en">37671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/35457" xml:lang="en">35457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/61651" xml:lang="en">61651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.technet.com/srd/archive/2010/01/12/ms10-001-font-file-decompression-vulnerability.aspx" xml:lang="en">http://blogs.technet.com/srd/archive/2010/01/12/ms10-001-font-file-decompression-vulnerability.aspx</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8324" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8324" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code via compressed data that represents a crafted EOT font, aka "Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0019">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:3.0.40818.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:3.0.40723.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:3.0.40624.00"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:3.0.40624.00"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:3.0.40723.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:3.0.40818.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:3.0.50106.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:silverlight:3.0.40624.00</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:3.0.40723.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:3.0.50106.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:3.0.40818.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0019</vuln:cve-id>
    <vuln:published-datetime>2010-08-11T14:47:49.813-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-09-17T01:44:08.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-08-12T11:54:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" xml:lang="en">TA10-222A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-060.mspx" xml:lang="en">MS10-060</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not properly handle pointers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and framework outage) via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:pro_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:pro_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0020</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:00.957-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:44.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T12:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8438" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8438" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-012.mspx" xml:lang="en">MS10-012</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8438" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8438" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:pro_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:pro_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0021</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:00.987-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:45.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T12:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8524" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8524" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-012.mspx" xml:lang="en">MS10-012</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8524" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8524" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:pro_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:pro_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0022</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:01.017-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:45.213-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T12:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8314" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8314" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-012.mspx" xml:lang="en">MS10-012</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8314" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8314" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0023</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:01.050-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T13:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8304" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8304" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-011.mspx" xml:lang="en">MS10-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38509" xml:lang="en">38509</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8304" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8304" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Local Privilege Elevation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2007:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2007:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2010:-:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2007:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:x32</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2007:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2010:-:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0024</vuln:cve-id>
    <vuln:published-datetime>2010-04-14T12:00:00.587-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:45.463-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-15T09:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7067" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7067" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" xml:lang="en">TA10-103A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-024.mspx" xml:lang="en">MS10-024</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7067" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7067" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2007:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2007:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2010:-:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2007:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:x32</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2007:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2010:-:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0025</vuln:cve-id>
    <vuln:published-datetime>2010-04-14T12:00:00.633-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T22:33:49.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-15T10:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12175" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12175" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" xml:lang="en">TA10-103A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-024.mspx" xml:lang="en">MS10-024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39253" xml:lang="en">39253</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12175" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12175" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command, aka "SMTP Memory Allocation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0026</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:01.063-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:45.683-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T13:33:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8006" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8006" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-010.mspx" xml:lang="en">MS10-010</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8006" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8006" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka "Hyper-V Instruction Set Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:8.0.6001"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0.5730.11"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0.5730:unknown:gold"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.00.6000.16441"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.00.6000.16386"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.00.5730.1100"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.01:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.00.5730.1100</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0.5730:unknown:gold</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.00.6000.16441</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.00.6000.16386</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0.5730.11</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:8.0.6001</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0027</vuln:cve-id>
    <vuln:published-datetime>2010-01-22T17:00:00.350-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-25T07:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8464" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8464" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-007.mspx" xml:lang="en">MS10-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx" xml:lang="en">MS10-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/55773" xml:lang="en">ie-url-code-execution(55773)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-10-016/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-10-016/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/509470/100/0/threaded" xml:lang="en">20100209 ZDI-10-016: Microsoft Windows ShellExecute Improper Sanitization Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8464" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8464" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0028</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:01.097-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:45.950-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T13:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8429" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8429" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-005.mspx" xml:lang="en">MS10-005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/36634" xml:lang="en">36634</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8429" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8429" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2002:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:powerpoint:2002:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0029</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:01.127-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:46.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T13:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8410" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8410" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx" xml:lang="en">MS10-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023563" xml:lang="en">1023563</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8410" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8410" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint File Path Handling Buffer Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2003:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:powerpoint:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0030</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:01.157-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:46.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T13:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8050" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8050" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx" xml:lang="en">MS10-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023563" xml:lang="en">1023563</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8050" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8050" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint LinkedSlideAtom Heap Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2003:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:powerpoint:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0031</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:01.173-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:46.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T14:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8081" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8081" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx" xml:lang="en">MS10-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023563" xml:lang="en">1023563</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8081" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8081" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0032">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2003:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:powerpoint:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0032</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:01.267-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:46.480-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T14:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8303" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8303" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx" xml:lang="en">MS10-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023563" xml:lang="en">1023563</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8303" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8303" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "OEPlaceholderAtom Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2003:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:powerpoint:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0033</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:01.300-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:46.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T14:28:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7711" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7711" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx" xml:lang="en">MS10-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023563" xml:lang="en">1023563</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7711" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7711" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2003:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:powerpoint:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0034</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:01.330-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:46.730-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T14:29:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8268" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8268" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx" xml:lang="en">MS10-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023563" xml:lang="en">1023563</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8268" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8268" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4:server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4:server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0035</vuln:cve-id>
    <vuln:published-datetime>2010-02-10T13:30:01.347-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:46.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-11T14:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:8428" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8428" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" xml:lang="en">TA10-040A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS10-014.mspx" xml:lang="en">MS10-014</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:8428" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:8428" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0036">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0036</vuln:cve-id>
    <vuln:published-datetime>2010-01-20T11:30:00.367-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-02-05T02:13:27.627-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-21T07:03:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/37868" xml:lang="en">37868</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/55746" xml:lang="en">macos-coreaudio-mp4-bo(55746)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0173" xml:lang="en">ADV-2010-0173</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023472" xml:lang="en">1023472</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4013" xml:lang="en">http://support.apple.com/kb/HT4013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4004" xml:lang="en">http://support.apple.com/kb/HT4004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38241" xml:lang="en">38241</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html" xml:lang="en">APPLE-SA-2010-01-19-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html" xml:lang="en">APPLE-SA-2010-02-02-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in CoreAudio in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 audio file.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0037">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0037</vuln:cve-id>
    <vuln:published-datetime>2010-01-20T11:30:00.413-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-01-23T02:14:06.267-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-21T07:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/55747" xml:lang="en">macos-imageraw-dng-bo(55747)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0173" xml:lang="en">ADV-2010-0173</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023473" xml:lang="en">1023473</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/37869" xml:lang="en">37869</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4004" xml:lang="en">http://support.apple.com/kb/HT4004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38241" xml:lang="en">38241</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html" xml:lang="en">APPLE-SA-2010-01-19-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted DNG image.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.1.2:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.0.1:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.0:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.0.2:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.0.2:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.0.0:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.0.0:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.0.1:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.0.1:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.4:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.3:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.4:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.2:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.1:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.3:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.2:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.5:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.2:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.1:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.5:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.2.1:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.2:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.1:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:2.2.1:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.0:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.1:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.1.0:-:ipodtouch"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.0.0:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.0.2:-:iphone"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:1.0.1:-:iphone"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:iphone_os:2.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.3:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.0</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.2.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.0</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.4:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.4:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.0</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.2</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.1:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.2.1:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.3:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.5:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.0.0:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.2:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.5:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.0.2:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.2:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.0:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.0.1:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.0.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.2:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.0.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.0.0:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.1:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.0.0:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.0.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.2:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.0:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.0.2:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:2.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.1.2:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.0:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:1.0.2:-:iphone</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0038</vuln:cve-id>
    <vuln:published-datetime>2010-02-03T14:30:00.437-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-26T01:36:36.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-04T12:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38040" xml:lang="en">38040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4013" xml:lang="en">http://support.apple.com/kb/HT4013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/62128" xml:lang="en">62128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html" xml:lang="en">APPLE-SA-2010-02-02-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch 1.1 through 3.1.2, allows physically proximate attackers to bypass device locking, and read or modify arbitrary data, via a USB control message that triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:apple:airport_extreme_base_station_firmware:5.5"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:airport_extreme_base_station_firmware:5.7"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:airport_express_base_station_firmware:6.1"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:airport_express_base_station_firmware:6.3"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:airport_express_base_station_firmware:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:airport_express_base_station_firmware:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:airport_express_base_station_firmware:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:airport_express_base_station_firmware:4.0.9"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:airport_express_base_station_firmware:3.84"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:apple:time_capsule"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:airport_extreme"/>
          <cpe-lang:fact-ref name="cpe:/h:apple:airport_express"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:apple:airport_express_base_station_firmware:6.3</vuln:product>
      <vuln:product>cpe:/h:apple:airport_express_base_station_firmware:7.4.2</vuln:product>
      <vuln:product>cpe:/h:apple:airport_extreme</vuln:product>
      <vuln:product>cpe:/h:apple:airport_express_base_station_firmware:4.0.9</vuln:product>
      <vuln:product>cpe:/h:apple:airport_express</vuln:product>
      <vuln:product>cpe:/h:apple:time_capsule</vuln:product>
      <vuln:product>cpe:/h:apple:airport_extreme_base_station_firmware:5.7</vuln:product>
      <vuln:product>cpe:/h:apple:airport_express_base_station_firmware:7.3.2</vuln:product>
      <vuln:product>cpe:/h:apple:airport_extreme_base_station_firmware:5.5</vuln:product>
      <vuln:product>cpe:/h:apple:airport_express_base_station_firmware:6.1</vuln:product>
      <vuln:product>cpe:/h:apple:airport_express_base_station_firmware:7.4.1</vuln:product>
      <vuln:product>cpe:/h:apple:airport_express_base_station_firmware:3.84</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0039</vuln:cve-id>
    <vuln:published-datetime>2010-12-21T22:00:01.390-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-01-19T01:53:52.307-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-12-22T11:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4298" xml:lang="en">http://support.apple.com/kb/HT4298</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Dec/msg00001.html" xml:lang="en">APPLE-SA-2010-12-16-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024907" xml:lang="en">1024907</vuln:reference>
    </vuln:references>
    <vuln:summary>The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's IP address for arbitrary intranet TCP traffic by leveraging write access to an intranet FTP server.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0040</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T09:28:25.277-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-24T01:42:29.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T10:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6741" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6741" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38674" xml:lang="en">38674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/56826" xml:lang="en">safari-colorsync-bo(56826)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023706" xml:lang="en">1023706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4105" xml:lang="en">http://support.apple.com/kb/HT4105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39135" xml:lang="en">39135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html" xml:lang="en">APPLE-SA-2010-03-30-2</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6741" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6741" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in ColorSync in Apple Safari before 4.0.5 on Windows, and iTunes before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with a crafted color profile that triggers a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0041">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0041</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T09:28:25.370-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-24T01:42:29.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T10:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6885" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6885" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38676" xml:lang="en">38676</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023706" xml:lang="en">1023706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4225" xml:lang="en">http://support.apple.com/kb/HT4225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4105" xml:lang="en">http://support.apple.com/kb/HT4105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39135" xml:lang="en">39135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" xml:lang="en">APPLE-SA-2010-06-21-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html" xml:lang="en">APPLE-SA-2010-03-30-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6885" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6885" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0042</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T09:28:25.403-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-12-10T01:37:13.297-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T11:11:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7561" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7561" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38677" xml:lang="en">38677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023706" xml:lang="en">1023706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4456" xml:lang="en">http://support.apple.com/kb/HT4456</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4225" xml:lang="en">http://support.apple.com/kb/HT4225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4105" xml:lang="en">http://support.apple.com/kb/HT4105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42314" xml:lang="en">42314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39135" xml:lang="en">39135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" xml:lang="en">APPLE-SA-2010-06-21-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" xml:lang="en">APPLE-SA-2010-11-22-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html" xml:lang="en">APPLE-SA-2010-03-30-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7561" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7561" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0043</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T09:28:25.433-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-24T01:42:30.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T11:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6901" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6901" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38673" xml:lang="en">38673</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023706" xml:lang="en">1023706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4225" xml:lang="en">http://support.apple.com/kb/HT4225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4105" xml:lang="en">http://support.apple.com/kb/HT4105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39135" xml:lang="en">39135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" xml:lang="en">APPLE-SA-2010-06-21-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html" xml:lang="en">APPLE-SA-2010-03-30-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6901" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6901" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0044">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0044</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T09:28:25.467-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:47.793-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T11:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7051" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7051" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38675" xml:lang="en">38675</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/56830" xml:lang="en">safari-pubsub-security-bypass(56830)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/62937" xml:lang="en">62937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7051" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7051" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>PubSub in Apple Safari before 4.0.5 does not properly implement use of the Accept Cookies preference to block cookies, which makes it easier for remote web servers to track users by setting a cookie in a (1) RSS or (2) Atom feed.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0:beta"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0:beta</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0045</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T09:28:25.497-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:47.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T11:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6817" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6817" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023706" xml:lang="en">1023706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6817" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6817" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Apple Safari before 4.0.5 on Windows does not properly validate external URL schemes, which allows remote attackers to open local files and execute arbitrary code via a crafted HTML document.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0046</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T09:28:25.527-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-17T22:45:34.953-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T11:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7053" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7053" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0552" xml:lang="en">ADV-2011-0552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0212" xml:lang="en">ADV-2011-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2722" xml:lang="en">ADV-2010-2722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1006-1" xml:lang="en">USN-1006-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023708" xml:lang="en">1023708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" xml:lang="en">MDVSA-2011:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4225" xml:lang="en">http://support.apple.com/kb/HT4225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43068" xml:lang="en">43068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41856" xml:lang="en">41856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" xml:lang="en">SUSE-SR:2011:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" xml:lang="en">FEDORA-2010-8423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" xml:lang="en">FEDORA-2010-8379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" xml:lang="en">FEDORA-2010-8360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" xml:lang="en">APPLE-SA-2010-06-21-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7053" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7053" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted format arguments.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0047</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T09:28:25.560-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-17T22:45:35.097-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T12:06:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6882" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6882" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0552" xml:lang="en">ADV-2011-0552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0212" xml:lang="en">ADV-2011-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2722" xml:lang="en">ADV-2010-2722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1006-1" xml:lang="en">USN-1006-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023708" xml:lang="en">1023708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" xml:lang="en">MDVSA-2011:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4225" xml:lang="en">http://support.apple.com/kb/HT4225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43068" xml:lang="en">43068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41856" xml:lang="en">41856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" xml:lang="en">SUSE-SR:2011:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" xml:lang="en">FEDORA-2010-8423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" xml:lang="en">FEDORA-2010-8379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" xml:lang="en">FEDORA-2010-8360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" xml:lang="en">APPLE-SA-2010-06-21-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6882" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6882" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "HTML object element fallback content."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0:beta</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0048</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T09:28:25.590-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-17T22:45:35.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T12:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7135" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7135" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0552" xml:lang="en">ADV-2011-0552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0212" xml:lang="en">ADV-2011-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2722" xml:lang="en">ADV-2010-2722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1006-1" xml:lang="en">USN-1006-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023708" xml:lang="en">1023708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" xml:lang="en">MDVSA-2011:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4225" xml:lang="en">http://support.apple.com/kb/HT4225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43068" xml:lang="en">43068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41856" xml:lang="en">41856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" xml:lang="en">SUSE-SR:2011:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" xml:lang="en">FEDORA-2010-8423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" xml:lang="en">FEDORA-2010-8379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" xml:lang="en">FEDORA-2010-8360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" xml:lang="en">APPLE-SA-2010-06-21-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7135" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7135" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML document.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0:beta</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0049</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T10:15:32.043-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-17T22:45:35.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T14:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6810" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6810" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0552" xml:lang="en">ADV-2011-0552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0212" xml:lang="en">ADV-2011-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2722" xml:lang="en">ADV-2010-2722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1006-1" xml:lang="en">USN-1006-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023708" xml:lang="en">1023708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" xml:lang="en">MDVSA-2011:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4225" xml:lang="en">http://support.apple.com/kb/HT4225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43068" xml:lang="en">43068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41856" xml:lang="en">41856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/62942" xml:lang="en">62942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" xml:lang="en">SUSE-SR:2011:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" xml:lang="en">FEDORA-2010-8423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" xml:lang="en">FEDORA-2010-8379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" xml:lang="en">FEDORA-2010-8360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" xml:lang="en">APPLE-SA-2010-06-21-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=863" xml:lang="en">20100311 Multiple Vendor WebKit HTML Element Use After Free Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6810" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6810" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via HTML elements with right-to-left (RTL) text directionality.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0050</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T10:15:32.073-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-17T22:45:35.643-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T14:40:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7587" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7587" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/56836" xml:lang="en">safari-nested-html-code-exec(56836)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0552" xml:lang="en">ADV-2011-0552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0212" xml:lang="en">ADV-2011-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2722" xml:lang="en">ADV-2010-2722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1006-1" xml:lang="en">USN-1006-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023708" xml:lang="en">1023708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" xml:lang="en">MDVSA-2011:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4225" xml:lang="en">http://support.apple.com/kb/HT4225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43068" xml:lang="en">43068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41856" xml:lang="en">41856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" xml:lang="en">SUSE-SR:2011:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" xml:lang="en">FEDORA-2010-8423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" xml:lang="en">FEDORA-2010-8379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" xml:lang="en">FEDORA-2010-8360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" xml:lang="en">APPLE-SA-2010-06-21-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7587" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7587" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0051</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T10:15:32.120-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-17T22:45:35.970-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T14:48:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7554" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7554" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/56837" xml:lang="en">safari-stylesheet-info-disclosure(56837)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0552" xml:lang="en">ADV-2011-0552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0212" xml:lang="en">ADV-2011-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2722" xml:lang="en">ADV-2010-2722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1006-1" xml:lang="en">USN-1006-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023708" xml:lang="en">1023708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" xml:lang="en">MDVSA-2011:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://websec.sv.cmu.edu/css/css.pdf" xml:lang="en">http://websec.sv.cmu.edu/css/css.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4456" xml:lang="en">http://support.apple.com/kb/HT4456</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4225" xml:lang="en">http://support.apple.com/kb/HT4225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43068" xml:lang="en">43068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42314" xml:lang="en">42314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41856" xml:lang="en">41856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html" xml:lang="en">http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/62944" xml:lang="en">62944</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" xml:lang="en">SUSE-SR:2011:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" xml:lang="en">APPLE-SA-2010-06-21-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" xml:lang="en">APPLE-SA-2010-11-22-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://code.google.com/p/chromium/issues/detail?id=9877" xml:lang="en">http://code.google.com/p/chromium/issues/detail?id=9877</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7554" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7554" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>WebKit in Apple Safari before 4.0.5 does not properly validate the cross-origin loading of stylesheets, which allows remote attackers to obtain sensitive information via a crafted HTML document.  NOTE: this might overlap CVE-2010-0651.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0052">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0:beta</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0052</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T10:15:32.153-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-17T22:45:36.347-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T14:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7403" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7403" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0552" xml:lang="en">ADV-2011-0552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0212" xml:lang="en">ADV-2011-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2722" xml:lang="en">ADV-2010-2722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1006-1" xml:lang="en">USN-1006-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023708" xml:lang="en">1023708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" xml:lang="en">MDVSA-2011:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4225" xml:lang="en">http://support.apple.com/kb/HT4225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43068" xml:lang="en">43068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41856" xml:lang="en">41856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" xml:lang="en">SUSE-SR:2011:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" xml:lang="en">FEDORA-2010-8423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" xml:lang="en">FEDORA-2010-8379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" xml:lang="en">FEDORA-2010-8360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" xml:lang="en">APPLE-SA-2010-06-21-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7403" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7403" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "callbacks for HTML elements."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0:beta</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0053</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T10:15:32.167-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-17T22:45:36.533-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T14:54:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7323" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7323" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0552" xml:lang="en">ADV-2011-0552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0212" xml:lang="en">ADV-2011-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2722" xml:lang="en">ADV-2010-2722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1006-1" xml:lang="en">USN-1006-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023708" xml:lang="en">1023708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" xml:lang="en">MDVSA-2011:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4225" xml:lang="en">http://support.apple.com/kb/HT4225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43068" xml:lang="en">43068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41856" xml:lang="en">41856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/62948" xml:lang="en">62948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" xml:lang="en">SUSE-SR:2011:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" xml:lang="en">FEDORA-2010-8423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" xml:lang="en">FEDORA-2010-8379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" xml:lang="en">FEDORA-2010-8360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" xml:lang="en">APPLE-SA-2010-06-21-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7323" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7323" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the run-in Cascading Style Sheets (CSS) display property.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0054</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T10:15:32.200-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-17T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T14:54:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6915" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6915" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38671" xml:lang="en">38671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0552" xml:lang="en">ADV-2011-0552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0212" xml:lang="en">ADV-2011-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2722" xml:lang="en">ADV-2010-2722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1006-1" xml:lang="en">USN-1006-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023708" xml:lang="en">1023708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" xml:lang="en">MDVSA-2011:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4225" xml:lang="en">http://support.apple.com/kb/HT4225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4070" xml:lang="en">http://support.apple.com/kb/HT4070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43068" xml:lang="en">43068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41856" xml:lang="en">41856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/62949" xml:lang="en">62949</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" xml:lang="en">SUSE-SR:2011:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" xml:lang="en">FEDORA-2010-8423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" xml:lang="en">FEDORA-2010-8379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" xml:lang="en">FEDORA-2010-8360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" xml:lang="en">APPLE-SA-2010-03-11-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" xml:lang="en">APPLE-SA-2010-06-21-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6915" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6915" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving HTML IMG elements.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0055</vuln:cve-id>
    <vuln:published-datetime>2010-03-30T14:30:00.327-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-31T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-31T10:44:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:summary>xar in Apple Mac OS X 10.5.8 does not properly validate package signatures, which allows attackers to have an unspecified impact via a modified package.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0056</vuln:cve-id>
    <vuln:published-datetime>2010-03-30T13:30:00.407-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-31T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-31T09:17:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Cocoa spell checking in AppKit in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0057</vuln:cve-id>
    <vuln:published-datetime>2010-03-30T13:30:00.483-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-31T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-31T09:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:summary>AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest access is disabled, which allows remote attackers to bypass intended access restrictions via a mount request.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0058</vuln:cve-id>
    <vuln:published-datetime>2010-03-30T13:30:00.517-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-31T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-31T10:02:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:summary>freshclam in ClamAV in Apple Mac OS X 10.5.8 with Security Update 2009-005 has an incorrect launchd.plist ProgramArguments key and consequently does not run, which might allow remote attackers to introduce viruses into the system.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0059</vuln:cve-id>
    <vuln:published-datetime>2010-03-30T13:30:00.563-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:49.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-31T10:13:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6922" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6922" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-10-041" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-10-041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/510517/100/0/threaded" xml:lang="en">20100402 ZDI-10-041: Apple QuickTime QDM2/QDCA Atom Remote Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" xml:lang="en">APPLE-SA-2010-03-30-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6922" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6922" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDM2 encoding, which triggers a buffer overflow due to inconsistent length fields, related to QDCA.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0060">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0060</vuln:cve-id>
    <vuln:published-datetime>2010-03-30T14:30:00.360-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:49.713-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-31T10:48:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7513" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7513" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" xml:lang="en">APPLE-SA-2010-03-30-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7513" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7513" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDMC encoding.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0062">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0062</vuln:cve-id>
    <vuln:published-datetime>2010-03-30T14:30:00.390-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-21T01:38:49.840-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-31T10:52:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6626" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6626" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-10-036" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-10-036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/510510/100/0/threaded" xml:lang="en">20100402 ZDI-10-036: Apple QuickTime H.263 PictureHeader Remote Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" xml:lang="en">APPLE-SA-2010-03-30-1</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6626" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6626" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed .3g2 movie file with H.263 encoding that triggers an incorrect buffer length calculation.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0063</vuln:cve-id>
    <vuln:published-datetime>2010-03-30T14:30:00.420-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-31T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-31T11:05:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari, as demonstrated by the values for the (1) .ibplugin and (2) .url extensions.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0064</vuln:cve-id>
    <vuln:published-datetime>2010-03-30T14:30:00.453-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-31T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-31T11:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:summary>DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to bypass intended disk-quota restrictions and have unspecified other impact by copying files owned by other users.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0065</vuln:cve-id>
    <vuln:published-datetime>2010-03-30T14:30:00.483-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-31T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-31T11:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4077" xml:lang="en">http://support.apple.com/kb/HT4077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" xml:lang="en">APPLE-SA-2010-03-29-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Disk Images in Apple Mac OS X before 10.6.3 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image with bzip2 compression.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:7.0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:10.1.4.2</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:7.0.4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0066</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:00.937-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:02.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T09:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023438" xml:lang="en">1023438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Access Manager Identity Server component in Oracle Application Server 7.0.4.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:10.1.3.4</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0067</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:00.953-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:03.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T09:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023438" xml:lang="en">1023438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 10.1.2.3 and 10.1.3.4 allows remote attackers to affect confidentiality via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:9.2:mp2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:10.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:bea_product_suite:9.2:mp2</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:9.1</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:10.0</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0068</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:00.983-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:03.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T09:41:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP2, and 10.0 allows remote attackers to affect confidentiality via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:7.0:sp7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:8.1:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:9.2:mp3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:10.0:mp1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:10.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:bea_product_suite:8.1:sp6</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:10.3.0</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:9.1</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:7.0</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:9.2:mp3</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:10.0:mp1</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:9.0</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:7.0:sp7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0069</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:01.013-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:04.100-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T09:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0, SP7, 8.1SP6, 9.0, 9.1, 9.2MP3, 10.0MP1, and 10.3.0 allows remote attackers to affect integrity via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0070">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:10.1.3.4</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0070</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:01.047-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:04.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T09:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023438" xml:lang="en">1023438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 10.1.2.3 and 10.1.3.4 allows remote attackers to affect integrity via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.0.8dv"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:11.1.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:11.1.0.7</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.0.8dv</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.1.0.5</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.0.8</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.2.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0071</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:01.077-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:04.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T09:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:secure_backup:10.2.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:secure_backup:10.2.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0072</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:01.107-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:04.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T10:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a buffer overflow in observiced.exe that allows remote attackers to execute arbitrary code via vectors related to a "reverse lookup of connections" to TCP port 10000.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:10.0:mp1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:6.1:sp7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server:10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:9.2:mp3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:7.0:sp7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_server_component:8.1:sp6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:8.1</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:10.0</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:10.3</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:10.0:mp1</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:9.2:mp3</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:9.0</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:9.2</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:7.0</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:6.1:sp7</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:8.1:sp6</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:6.1</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:9.1</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server:10.3</vuln:product>
      <vuln:product>cpe:/a:oracle:weblogic_server_component:7.0:sp7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0073</vuln:cve-id>
    <vuln:published-datetime>2010-04-14T13:30:00.367-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-04-17T01:40:31.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-15T19:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" xml:lang="en">TA10-103B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0216" xml:lang="en">ADV-2010-0216</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0073.html" xml:lang="en">http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0073.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39439" xml:lang="en">39439</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the WebLogic Server in Oracle WebLogic Server 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, and 10.3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:7.0:sp7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:8.1:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:9.2:mp3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:10.0:mp2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:10.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:bea_product_suite:8.1:sp6</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:10.3.1</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:10.0:mp2</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:9.1</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:9.2:mp3</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:9.0</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:7.0:sp7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0074</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:01.140-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:04.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T10:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0SP7, 8.1SP6, 9.0, 9.1, 9.2MP3, 10.0MP2, and 10.3.1 allows remote attackers to affect availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.5.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:12.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:12.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:e-business_suite:12.1.1</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:12.0.6</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.5.10.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0075</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:01.170-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:05.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T10:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Oracle HRMS (Self Service) component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database:3.2.1.00.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database:3.2.1.00.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0076</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:01.187-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:05.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T10:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Application Express Application Builder component in Oracle Database 3.2.1.00.10 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.5.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:12.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:12.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:e-business_suite:12.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:12.0.6</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.5.10.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0077</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:01.217-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:05.490-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T10:46:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the CRM Technical Foundation (mobile) component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:10.0:mp2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:9.2:mp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:bea_product_suite:10.3.1</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:10.0:mp2</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:9.1</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:9.2:mp3</vuln:product>
      <vuln:product>cpe:/a:oracle:bea_product_suite:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0078</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:01.250-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:05.693-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T10:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP3, 10.0MP2, and 10.3.1 allows remote attackers to affect availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:oracle:bea_product_suite:r27.6.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:bea_product_suite:r27.6.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0079</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:01.280-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:05.943-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T10:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this CVE identifier overlaps CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, and CVE-2009-3877.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:peoplesoft_enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:jd_edwards_enterpriseone:8.9:bundle21"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:jd_edwards_enterpriseone:9.0:bundle11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:jd_edwards_enterpriseone:8.9:bundle21</vuln:product>
      <vuln:product>cpe:/a:oracle:jd_edwards_enterpriseone:9.0:bundle11</vuln:product>
      <vuln:product>cpe:/a:oracle:peoplesoft_enterprise</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0080</vuln:cve-id>
    <vuln:published-datetime>2010-01-12T20:30:01.310-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:06.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-13T10:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" xml:lang="en">TA10-012A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the PeopleSoft Enterprise HCM - eProfile component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9 Bundle, #21 and 9.0 Bundle #11 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:fusion_middleware:10.1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:fusion_middleware:10.1.4.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:fusion_middleware:10.1.4.0.1</vuln:product>
      <vuln:product>cpe:/a:oracle:fusion_middleware:10.1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0081</vuln:cve-id>
    <vuln:published-datetime>2010-07-13T17:30:00.920-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:06.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-07-14T10:12:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Application Server Control component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1 allows remote authenticated users to affect integrity via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1_b06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01a"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_07"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_25"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_26"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_07"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_25"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_26"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01a"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_07"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_25"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_26"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_04</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_05</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update9</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_03</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_03</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_02</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_06</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_04</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_07</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_08</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1_b06</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_27</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_27</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_01</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_11</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_24</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_01a</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_17</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_04</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_02</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_08</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_03</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_04</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_09</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_27</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_25</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_06</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_07</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_22</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_26</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_26</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_06</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_25</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_25</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_08</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_07</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_26</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_03</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_22</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_09</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_01a</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_04</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_03</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_09</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0082</vuln:cve-id>
    <vuln:published-datetime>2010-04-01T12:30:00.343-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:06.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-01T20:50:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:13934" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13934" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11576" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11576" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1793" xml:lang="en">ADV-2010-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1191" xml:lang="en">ADV-2010-1191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1107" xml:lang="en">ADV-2010-1107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0339.html" xml:lang="en">RHSA-2010:0339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0338.html" xml:lang="en">RHSA-2010:0338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0337.html" xml:lang="en">RHSA-2010:0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" xml:lang="en">MDVSA-2010:084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-923-1" xml:lang="en">USN-923-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4171" xml:lang="en">http://support.apple.com/kb/HT4171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4170" xml:lang="en">http://support.apple.com/kb/HT4170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43308" xml:lang="en">43308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40545" xml:lang="en">40545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39819" xml:lang="en">39819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39317" xml:lang="en">39317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39292" xml:lang="en">39292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" xml:lang="en">SUSE-SR:2010:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" xml:lang="en">SUSE-SR:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" xml:lang="en">APPLE-SA-2010-05-18-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" xml:lang="en">APPLE-SA-2010-05-18-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">HPSBMA02547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">HPSBMA02547</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11576" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11576" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:13934" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:13934" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:oracle:opensolaris:8"/>
        <cpe-lang:fact-ref name="cpe:/o:oracle:opensolaris:9"/>
        <cpe-lang:fact-ref name="cpe:/o:oracle:opensolaris:10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:oracle:opensolaris:10</vuln:product>
      <vuln:product>cpe:/o:oracle:opensolaris:9</vuln:product>
      <vuln:product>cpe:/o:oracle:opensolaris:8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0083</vuln:cve-id>
    <vuln:published-datetime>2010-07-13T18:30:01.547-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:06.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-07-14T10:19:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle OpenSolaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1_b06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1_b06</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update8</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update6</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0084</vuln:cve-id>
    <vuln:published-datetime>2010-04-01T12:30:00.437-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:07.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-02T08:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14061" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14061" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11120" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11120" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1793" xml:lang="en">ADV-2010-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1454" xml:lang="en">ADV-2010-1454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1191" xml:lang="en">ADV-2010-1191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1107" xml:lang="en">ADV-2010-1107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0471.html" xml:lang="en">RHSA-2010:0471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0383.html" xml:lang="en">RHSA-2010:0383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0339.html" xml:lang="en">RHSA-2010:0339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0338.html" xml:lang="en">RHSA-2010:0338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0337.html" xml:lang="en">RHSA-2010:0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" xml:lang="en">MDVSA-2010:084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-923-1" xml:lang="en">USN-923-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4171" xml:lang="en">http://support.apple.com/kb/HT4171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4170" xml:lang="en">http://support.apple.com/kb/HT4170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43308" xml:lang="en">43308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40545" xml:lang="en">40545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39819" xml:lang="en">39819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39659" xml:lang="en">39659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39317" xml:lang="en">39317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39292" xml:lang="en">39292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/63482" xml:lang="en">63482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" xml:lang="en">SUSE-SR:2010:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" xml:lang="en">SUSE-SR:2010:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" xml:lang="en">SUSE-SR:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" xml:lang="en">APPLE-SA-2010-05-18-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" xml:lang="en">APPLE-SA-2010-05-18-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">HPSBMA02547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">HPSBMA02547</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14061" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14061" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11120" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11120" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1_b06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01a"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_07"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_25"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_26"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_07"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_25"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_26"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01a"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_07"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_25"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_26"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_04</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_05</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update9</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_03</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_03</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_02</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_06</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_04</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_07</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_08</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1_b06</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_27</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_27</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_01</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_11</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_24</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_01a</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_17</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_04</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_02</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_08</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_03</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_04</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_09</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_27</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_25</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_06</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_07</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_22</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_26</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_26</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_06</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_25</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_25</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_08</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_07</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_26</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_03</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_22</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_09</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_01a</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_04</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_03</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_09</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0085</vuln:cve-id>
    <vuln:published-datetime>2010-04-01T12:30:00.530-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:07.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-02T10:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:13803" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13803" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10474" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10474" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1793" xml:lang="en">ADV-2010-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1454" xml:lang="en">ADV-2010-1454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1191" xml:lang="en">ADV-2010-1191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1107" xml:lang="en">ADV-2010-1107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0471.html" xml:lang="en">RHSA-2010:0471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0383.html" xml:lang="en">RHSA-2010:0383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0339.html" xml:lang="en">RHSA-2010:0339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0338.html" xml:lang="en">RHSA-2010:0338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0337.html" xml:lang="en">RHSA-2010:0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" xml:lang="en">MDVSA-2010:084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-923-1" xml:lang="en">USN-923-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4171" xml:lang="en">http://support.apple.com/kb/HT4171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4170" xml:lang="en">http://support.apple.com/kb/HT4170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43308" xml:lang="en">43308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40545" xml:lang="en">40545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39819" xml:lang="en">39819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39659" xml:lang="en">39659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39317" xml:lang="en">39317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39292" xml:lang="en">39292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" xml:lang="en">SUSE-SR:2010:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" xml:lang="en">SUSE-SR:2010:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" xml:lang="en">SUSE-SR:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" xml:lang="en">APPLE-SA-2010-05-18-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" xml:lang="en">APPLE-SA-2010-05-18-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">HPSBMA02547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">HPSBMA02547</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:13803" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:13803" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10474" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10474" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:fusion_middleware:10.1.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:fusion_middleware:10.1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0086</vuln:cve-id>
    <vuln:published-datetime>2010-04-13T18:30:00.337-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:07.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-14T10:19:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" xml:lang="en">TA10-103B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023869" xml:lang="en">1023869</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpuapr2010-099504.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpuapr2010-099504.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39439" xml:lang="en">39439</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1_b06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01a"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_07"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_25"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_26"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_07"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_25"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_26"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01a"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_07"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_25"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_26"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_04</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_05</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update9</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_03</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_03</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_02</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_06</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_04</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_07</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_08</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1_b06</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_27</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_27</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_01</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_11</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_24</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_01a</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_17</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_04</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_02</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_08</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_03</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_04</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_09</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_27</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_25</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_06</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_07</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_22</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_26</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_26</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_06</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_25</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_25</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_08</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_07</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_26</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_03</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_22</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_09</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_01a</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_04</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_03</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_09</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0087</vuln:cve-id>
    <vuln:published-datetime>2010-04-01T12:30:00.563-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:07.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-02T10:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:13959" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13959" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1793" xml:lang="en">ADV-2010-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1454" xml:lang="en">ADV-2010-1454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1191" xml:lang="en">ADV-2010-1191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0471.html" xml:lang="en">RHSA-2010:0471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0383.html" xml:lang="en">RHSA-2010:0383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0338.html" xml:lang="en">RHSA-2010:0338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0337.html" xml:lang="en">RHSA-2010:0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4171" xml:lang="en">http://support.apple.com/kb/HT4171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4170" xml:lang="en">http://support.apple.com/kb/HT4170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43308" xml:lang="en">43308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40545" xml:lang="en">40545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39819" xml:lang="en">39819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39659" xml:lang="en">39659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39317" xml:lang="en">39317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" xml:lang="en">SUSE-SR:2010:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" xml:lang="en">SUSE-SR:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" xml:lang="en">APPLE-SA-2010-05-18-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" xml:lang="en">APPLE-SA-2010-05-18-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">SSRT100179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">SSRT100179</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:13959" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:13959" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1_b06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.0_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_01a"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_07"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_25"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_26"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.3.1_27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_07"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_25"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_26"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1_27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.0_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01a"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_04"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_05"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_07"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_25"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_26"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_04</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_05</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update9</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_03</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_03</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_02</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_06</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_04</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_07</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_08</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1_b06</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_27</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_27</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_01</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_11</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_24</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_01a</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_17</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_04</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_02</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_08</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0_03</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_04</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_09</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_27</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_25</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_06</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_07</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_22</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_26</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_26</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_06</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_25</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_25</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_08</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.0</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_07</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_26</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.0_03</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_05</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_22</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_09</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_01a</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1_04</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_03</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.3.1_09</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0088</vuln:cve-id>
    <vuln:published-datetime>2010-04-01T12:30:00.593-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:07.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-02T10:32:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14321" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14321" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11173" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11173" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1793" xml:lang="en">ADV-2010-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1454" xml:lang="en">ADV-2010-1454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1191" xml:lang="en">ADV-2010-1191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1107" xml:lang="en">ADV-2010-1107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0471.html" xml:lang="en">RHSA-2010:0471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0383.html" xml:lang="en">RHSA-2010:0383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0339.html" xml:lang="en">RHSA-2010:0339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0338.html" xml:lang="en">RHSA-2010:0338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0337.html" xml:lang="en">RHSA-2010:0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" xml:lang="en">MDVSA-2010:084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-923-1" xml:lang="en">USN-923-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4171" xml:lang="en">http://support.apple.com/kb/HT4171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4170" xml:lang="en">http://support.apple.com/kb/HT4170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43308" xml:lang="en">43308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40545" xml:lang="en">40545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39819" xml:lang="en">39819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39659" xml:lang="en">39659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39317" xml:lang="en">39317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39292" xml:lang="en">39292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" xml:lang="en">SUSE-SR:2010:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" xml:lang="en">SUSE-SR:2010:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" xml:lang="en">SUSE-SR:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" xml:lang="en">APPLE-SA-2010-05-18-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" xml:lang="en">APPLE-SA-2010-05-18-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">HPSBMA02547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">HPSBMA02547</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14321" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14321" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11173" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11173" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1_b06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1_b06</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update8</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update6</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0089</vuln:cve-id>
    <vuln:published-datetime>2010-04-01T12:30:00.627-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:08.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-02T10:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14208" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14208" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1793" xml:lang="en">ADV-2010-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1454" xml:lang="en">ADV-2010-1454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1191" xml:lang="en">ADV-2010-1191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0471.html" xml:lang="en">RHSA-2010:0471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0383.html" xml:lang="en">RHSA-2010:0383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0338.html" xml:lang="en">RHSA-2010:0338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0337.html" xml:lang="en">RHSA-2010:0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4171" xml:lang="en">http://support.apple.com/kb/HT4171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4170" xml:lang="en">http://support.apple.com/kb/HT4170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43308" xml:lang="en">43308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40545" xml:lang="en">40545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39819" xml:lang="en">39819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39659" xml:lang="en">39659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39317" xml:lang="en">39317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" xml:lang="en">SUSE-SR:2010:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" xml:lang="en">SUSE-SR:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" xml:lang="en">APPLE-SA-2010-05-18-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" xml:lang="en">APPLE-SA-2010-05-18-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">SSRT100179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">SSRT100179</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14208" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14208" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0090">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1_b06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1_b06</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0090</vuln:cve-id>
    <vuln:published-datetime>2010-04-01T12:30:00.640-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:08.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-02T10:51:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14237" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14237" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1793" xml:lang="en">ADV-2010-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1454" xml:lang="en">ADV-2010-1454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1191" xml:lang="en">ADV-2010-1191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0471.html" xml:lang="en">RHSA-2010:0471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0383.html" xml:lang="en">RHSA-2010:0383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0337.html" xml:lang="en">RHSA-2010:0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4171" xml:lang="en">http://support.apple.com/kb/HT4171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4170" xml:lang="en">http://support.apple.com/kb/HT4170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43308" xml:lang="en">43308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40545" xml:lang="en">40545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39819" xml:lang="en">39819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39659" xml:lang="en">39659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39317" xml:lang="en">39317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" xml:lang="en">SUSE-SR:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" xml:lang="en">APPLE-SA-2010-05-18-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" xml:lang="en">APPLE-SA-2010-05-18-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">SSRT100179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">SSRT100179</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14237" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14237" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18 allows remote attackers to affect integrity and availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1_b06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1_b06</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update8</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update6</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0091</vuln:cve-id>
    <vuln:published-datetime>2010-04-01T12:30:00.687-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:08.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-02T11:02:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9855" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9855" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:13492" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13492" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1793" xml:lang="en">ADV-2010-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1454" xml:lang="en">ADV-2010-1454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1191" xml:lang="en">ADV-2010-1191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1107" xml:lang="en">ADV-2010-1107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0471.html" xml:lang="en">RHSA-2010:0471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0383.html" xml:lang="en">RHSA-2010:0383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0339.html" xml:lang="en">RHSA-2010:0339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0338.html" xml:lang="en">RHSA-2010:0338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0337.html" xml:lang="en">RHSA-2010:0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" xml:lang="en">MDVSA-2010:084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-923-1" xml:lang="en">USN-923-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4171" xml:lang="en">http://support.apple.com/kb/HT4171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4170" xml:lang="en">http://support.apple.com/kb/HT4170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43308" xml:lang="en">43308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40545" xml:lang="en">40545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39819" xml:lang="en">39819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39659" xml:lang="en">39659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39317" xml:lang="en">39317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39292" xml:lang="en">39292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/63481" xml:lang="en">63481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" xml:lang="en">SUSE-SR:2010:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" xml:lang="en">SUSE-SR:2010:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" xml:lang="en">SUSE-SR:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" xml:lang="en">APPLE-SA-2010-05-18-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" xml:lang="en">APPLE-SA-2010-05-18-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">SSRT100179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">SSRT100179</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9855" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9855" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:13492" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:13492" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0092">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1_b06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1_b06</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0092</vuln:cve-id>
    <vuln:published-datetime>2010-04-01T12:30:00.703-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:09.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-02T11:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14210" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14210" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10057" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10057" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1793" xml:lang="en">ADV-2010-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1454" xml:lang="en">ADV-2010-1454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1191" xml:lang="en">ADV-2010-1191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1107" xml:lang="en">ADV-2010-1107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0471.html" xml:lang="en">RHSA-2010:0471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0383.html" xml:lang="en">RHSA-2010:0383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0339.html" xml:lang="en">RHSA-2010:0339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0338.html" xml:lang="en">RHSA-2010:0338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0337.html" xml:lang="en">RHSA-2010:0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" xml:lang="en">MDVSA-2010:084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-923-1" xml:lang="en">USN-923-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4171" xml:lang="en">http://support.apple.com/kb/HT4171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4170" xml:lang="en">http://support.apple.com/kb/HT4170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43308" xml:lang="en">43308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40545" xml:lang="en">40545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39819" xml:lang="en">39819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39659" xml:lang="en">39659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39317" xml:lang="en">39317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39292" xml:lang="en">39292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" xml:lang="en">SUSE-SR:2010:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" xml:lang="en">SUSE-SR:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" xml:lang="en">APPLE-SA-2010-05-18-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" xml:lang="en">APPLE-SA-2010-05-18-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">SSRT100179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">SSRT100179</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10057" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10057" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14210" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14210" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1_b06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1_b06</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update8</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update6</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0093</vuln:cve-id>
    <vuln:published-datetime>2010-04-01T12:30:00.733-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:09.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-02T11:37:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9877" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9877" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14288" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14288" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1793" xml:lang="en">ADV-2010-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1191" xml:lang="en">ADV-2010-1191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1107" xml:lang="en">ADV-2010-1107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0339.html" xml:lang="en">RHSA-2010:0339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0338.html" xml:lang="en">RHSA-2010:0338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0337.html" xml:lang="en">RHSA-2010:0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" xml:lang="en">MDVSA-2010:084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-923-1" xml:lang="en">USN-923-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4171" xml:lang="en">http://support.apple.com/kb/HT4171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4170" xml:lang="en">http://support.apple.com/kb/HT4170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43308" xml:lang="en">43308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40545" xml:lang="en">40545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39819" xml:lang="en">39819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39317" xml:lang="en">39317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39292" xml:lang="en">39292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/63485" xml:lang="en">63485</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" xml:lang="en">SUSE-SR:2010:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" xml:lang="en">SUSE-SR:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" xml:lang="en">APPLE-SA-2010-05-18-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" xml:lang="en">APPLE-SA-2010-05-18-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">HPSBMA02547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">HPSBMA02547</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14288" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14288" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9877" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9877" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1_b06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1_b06</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0094</vuln:cve-id>
    <vuln:published-datetime>2010-04-01T12:30:00.767-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:09.803-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-02T11:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14351" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14351" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:10851" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10851" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-10-051" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-10-051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1793" xml:lang="en">ADV-2010-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1454" xml:lang="en">ADV-2010-1454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1191" xml:lang="en">ADV-2010-1191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1107" xml:lang="en">ADV-2010-1107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/510527/100/0/threaded" xml:lang="en">20100405 ZDI-10-051: Sun Java Runtime RMIConnectionImpl Privileged Context Remote Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0471.html" xml:lang="en">RHSA-2010:0471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0383.html" xml:lang="en">RHSA-2010:0383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0339.html" xml:lang="en">RHSA-2010:0339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0338.html" xml:lang="en">RHSA-2010:0338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0337.html" xml:lang="en">RHSA-2010:0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" xml:lang="en">MDVSA-2010:084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-923-1" xml:lang="en">USN-923-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4171" xml:lang="en">http://support.apple.com/kb/HT4171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4170" xml:lang="en">http://support.apple.com/kb/HT4170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43308" xml:lang="en">43308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40545" xml:lang="en">40545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39819" xml:lang="en">39819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39659" xml:lang="en">39659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39317" xml:lang="en">39317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39292" xml:lang="en">39292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" xml:lang="en">SUSE-SR:2010:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" xml:lang="en">SUSE-SR:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" xml:lang="en">APPLE-SA-2010-05-18-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" xml:lang="en">APPLE-SA-2010-05-18-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">SSRT100179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">SSRT100179</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14351" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14351" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:10851" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:10851" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update1_b06"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.6.0:update_18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_02"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_14"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_15"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_17"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_19"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_20"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_21"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_22"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_23"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_24"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update15</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update20</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_20</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_4</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_25</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1_b06</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update2</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_18</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_14</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_14</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_02</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_24</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_21</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update21</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update8</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update14</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update23</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_13</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_23</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_17</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_15</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_12</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_15</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_22</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.6.0:update_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update19</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_17</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.6.0:update_5</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2:update6</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0095</vuln:cve-id>
    <vuln:published-datetime>2010-04-01T12:30:00.797-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-22T23:17:09.990-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-02T11:59:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14105" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14105" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11621" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11621" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1793" xml:lang="en">ADV-2010-1793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1454" xml:lang="en">ADV-2010-1454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1191" xml:lang="en">ADV-2010-1191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1107" xml:lang="en">ADV-2010-1107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" xml:lang="en">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" xml:lang="en">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" xml:lang="en">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0471.html" xml:lang="en">RHSA-2010:0471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0383.html" xml:lang="en">RHSA-2010:0383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0339.html" xml:lang="en">RHSA-2010:0339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0338.html" xml:lang="en">RHSA-2010:0338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2010-0337.html" xml:lang="en">RHSA-2010:0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" xml:lang="en">MDVSA-2010:084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-923-1" xml:lang="en">USN-923-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4171" xml:lang="en">http://support.apple.com/kb/HT4171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4170" xml:lang="en">http://support.apple.com/kb/HT4170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43308" xml:lang="en">43308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40545" xml:lang="en">40545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39819" xml:lang="en">39819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39659" xml:lang="en">39659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39317" xml:lang="en">39317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39292" xml:lang="en">39292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" xml:lang="en">SUSE-SR:2010:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" xml:lang="en">SUSE-SR:2010:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" xml:lang="en">SUSE-SR:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" xml:lang="en">APPLE-SA-2010-05-18-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" xml:lang="en">APPLE-SA-2010-05-18-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">HPSBMA02547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" xml:lang="en">HPSBMA02547</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11621" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11621" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14105" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14105" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.2:p3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0a6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0b1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0b2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0b4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.3p1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.3p2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.3p3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.3p4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0-p1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0-p2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0a1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0a2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0a3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0a4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0a5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0a6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0b1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0b2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0b3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.1b1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.1b2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.1b3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.2p1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.6.0:p1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.6.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.6.0a1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.6.1:p1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.6.1:p2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:bind:9.2.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0a6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0a4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0a3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.6.0:p1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.6.1:p2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0b1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0a3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.2:p3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.6.1:p1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0b4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0a5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0b1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0b3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0a2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.3p4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0-p1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.1b2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.7</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.6.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0a1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0a5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.1b1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.1b3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.3p1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.1:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.6.0:rc2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.6.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0a6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.3p3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.9</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0b2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0a4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0a1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.3p2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.6.0a1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0a2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.2p1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0b2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0-p2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0097</vuln:cve-id>
    <vuln:published-datetime>2010-01-22T17:00:00.397-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-20T22:41:19.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-25T07:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:9357" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9357" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7430" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7430" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7212" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7212" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12205" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12205" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/360341" xml:lang="en">VU#360341</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.isc.org/advisories/CVE-2010-0097" xml:lang="en">https://www.isc.org/advisories/CVE-2010-0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2010-0095.html" xml:lang="en">RHSA-2010:0095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2010-0062.html" xml:lang="en">RHSA-2010:0062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=554851" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=554851</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/55753" xml:lang="en">bind-dnssecnsec-cache-poisoning(55753)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1352" xml:lang="en">ADV-2010-1352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0981" xml:lang="en">ADV-2010-0981</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0622" xml:lang="en">ADV-2010-0622</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0176" xml:lang="en">ADV-2010-0176</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-888-1" xml:lang="en">USN-888-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/37865" xml:lang="en">37865</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/61853" xml:lang="en">61853</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:021" xml:lang="en">MDVSA-2010:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2010/dsa-2054" xml:lang="en">DSA-2054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018" xml:lang="en">http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5002" xml:lang="en">http://support.apple.com/kb/HT5002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021798.1-1" xml:lang="en">1021798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1023474" xml:lang="en">1023474</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40086" xml:lang="en">40086</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39582" xml:lang="en">39582</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39334" xml:lang="en">39334</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38240" xml:lang="en">38240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38219" xml:lang="en">38219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38169" xml:lang="en">38169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=127195582210247&amp;w=2" xml:lang="en">SSRT100004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=127195582210247&amp;w=2" xml:lang="en">SSRT100004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html" xml:lang="en">SUSE-SA:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034202.html" xml:lang="en">FEDORA-2010-0868</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034196.html" xml:lang="en">FEDORA-2010-0861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" xml:lang="en">APPLE-SA-2011-10-12-3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txt" xml:lang="en">ftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txt</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7212" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7212" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:9357" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:9357" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7430" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7430" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12205" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12205" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0098">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.01"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.02"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.03"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.05"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.14:pre"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.51"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.52"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.53"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.54"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.60p"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.65"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.66"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.67"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.67-1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.68"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.68.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.70"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.70:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.71"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.72"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.73"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.74"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.75"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.75.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.80"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.80:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.80:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.80:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.80:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.81"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.82"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.83"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.84"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.85"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.85.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.86"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.86.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.86.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.87"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.87.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.88"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.88.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.88.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.88.3"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.88.4"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.88.5"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.88.6"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.88.7"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.90"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.90.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.90.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.90.3"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.91"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.91.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.91.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.92"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.92.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.93"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.93.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.93.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.93.3"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.94"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.94.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.94.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.95"/>
        <cpe-lang:fact-ref name="cpe:/a:clamavs:clamav:0.04"/>
        <cpe-lang:fact-ref name="cpe:/a:clamavs:clamav:0.06"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.84:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.84:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.86:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.9:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.90:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.90:rc1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.90:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.90:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.91:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.91:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.95:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.95:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.95.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.95.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.95.3"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.96:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.96:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:clamav:clamav:0.14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clamav:clamav:0.90.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.02</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.93.2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.86.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.91.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.93.3</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.95.3</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.93.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.3</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.14</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.96:rc2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.84</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.90.2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.21</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.86.2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.70</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.80:rc2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.53</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.68</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.95</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.68.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.88.5</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.14:pre</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.80</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.71</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.75.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.13</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.88.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.20</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.80:rc4</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.54</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.70:rc</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.86:rc1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.94.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.90:rc3</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.90.3</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.88.7</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.10</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.95:rc1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.91.2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.75</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.93</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.88.2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.05</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.94.2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.51</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.85</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.90:rc1.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.86</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.60p</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.67</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.88.4</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.12</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.87.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.95:rc2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.92</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.91:rc1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.90</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.03</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.91</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.65</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.67-1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.60</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.23</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.80:rc3</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.73</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.74</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.80:rc</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.85.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.15</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.95.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.9:rc1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.88.6</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.95.2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.92.1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.84:rc1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.22</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.01</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.91:rc2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.81</vuln:product>
      <vuln:product>cpe:/a:clamavs:clamav:0.06</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.84:rc2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.72</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.94</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.66</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.90:rc1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.24</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.52</vuln:product>
      <vuln:product>cpe:/a:clamavs:clamav:0.04</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.82</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.96:rc1</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.88.3</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.88</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.87</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.90:rc2</vuln:product>
      <vuln:product>cpe:/a:clamav:clamav:0.83</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0098</vuln:cve-id>
    <vuln:published-datetime>2010-04-08T13:30:00.313-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-08-31T01:41:20.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-09T10:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/39262" xml:lang="en">39262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1826" xml:lang="en">https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1826</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1206" xml:lang="en">ADV-2010-1206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1001" xml:lang="en">ADV-2010-1001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0909" xml:lang="en">ADV-2010-0909</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0832" xml:lang="en">ADV-2010-0832</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0827" xml:lang="en">ADV-2010-0827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-926-1" xml:lang="en">USN-926-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/04/08/3" xml:lang="en">[oss-security] 20100407 Re: ClamAV small issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/04/06/4" xml:lang="en">[oss-security] 20100406 ClamAV small issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:082" xml:lang="en">MDVSA-2010:082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4312" xml:lang="en">http://support.apple.com/kb/HT4312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39656" xml:lang="en">39656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39329" xml:lang="en">39329</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39293" xml:lang="en">39293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html" xml:lang="en">SUSE-SR:2010:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html" xml:lang="en">APPLE-SA-2010-08-24-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96" xml:lang="en">http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96</vuln:reference>
    </vuln:references>
    <vuln:summary>ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0099">
    <vuln:cve-id>CVE-2010-0099</vuln:cve-id>
    <vuln:published-datetime>2010-07-22T12:30:01.017-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-07-22T12:30:01.297-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-0092.  Reason: This candidate is a duplicate of CVE-2010-0092.  Notes: All CVE users should reference CVE-2010-0092 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0101">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x94x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x86x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x85x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x782e"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x772e"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x73x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x65x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x644"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x646"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x64xef"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x642"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x546"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x543"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x544"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x46x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x36x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x26x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x20x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:w840"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:w850"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:t656"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:t650"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:t652"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:t654"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:t64x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:n4000"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:n4050e"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:n70xxe"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:n8120"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:n8130"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e462"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e460"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e450"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e360dn"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e260"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e360d"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:c935dn"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:c920"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:c78x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:c77x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:c73x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:c546"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:c540"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:c543"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:c544"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:c53x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:c52x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:25xxn"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x422"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:x34x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:t430"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e350"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e34x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e33x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e23x"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e250"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e240n"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e240"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e238"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:e120"/>
        <cpe-lang:fact-ref name="cpe:/h:lexmark:c510"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:lexmark:c53x</vuln:product>
      <vuln:product>cpe:/h:lexmark:e350</vuln:product>
      <vuln:product>cpe:/h:lexmark:n4000</vuln:product>
      <vuln:product>cpe:/h:lexmark:e240n</vuln:product>
      <vuln:product>cpe:/h:lexmark:n8130</vuln:product>
      <vuln:product>cpe:/h:lexmark:x646</vuln:product>
      <vuln:product>cpe:/h:lexmark:e250</vuln:product>
      <vuln:product>cpe:/h:lexmark:x65x</vuln:product>
      <vuln:product>cpe:/h:lexmark:e238</vuln:product>
      <vuln:product>cpe:/h:lexmark:x94x</vuln:product>
      <vuln:product>cpe:/h:lexmark:x46x</vuln:product>
      <vuln:product>cpe:/h:lexmark:e240</vuln:product>
      <vuln:product>cpe:/h:lexmark:c73x</vuln:product>
      <vuln:product>cpe:/h:lexmark:t654</vuln:product>
      <vuln:product>cpe:/h:lexmark:x422</vuln:product>
      <vuln:product>cpe:/h:lexmark:x34x</vuln:product>
      <vuln:product>cpe:/h:lexmark:c510</vuln:product>
      <vuln:product>cpe:/h:lexmark:t650</vuln:product>
      <vuln:product>cpe:/h:lexmark:c935dn</vuln:product>
      <vuln:product>cpe:/h:lexmark:c78x</vuln:product>
      <vuln:product>cpe:/h:lexmark:x73x</vuln:product>
      <vuln:product>cpe:/h:lexmark:n8120</vuln:product>
      <vuln:product>cpe:/h:lexmark:w850</vuln:product>
      <vuln:product>cpe:/h:lexmark:e33x</vuln:product>
      <vuln:product>cpe:/h:lexmark:c544</vuln:product>
      <vuln:product>cpe:/h:lexmark:t652</vuln:product>
      <vuln:product>cpe:/h:lexmark:x544</vuln:product>
      <vuln:product>cpe:/h:lexmark:x782e</vuln:product>
      <vuln:product>cpe:/h:lexmark:c540</vuln:product>
      <vuln:product>cpe:/h:lexmark:x86x</vuln:product>
      <vuln:product>cpe:/h:lexmark:x36x</vuln:product>
      <vuln:product>cpe:/h:lexmark:x546</vuln:product>
      <vuln:product>cpe:/h:lexmark:n4050e</vuln:product>
      <vuln:product>cpe:/h:lexmark:c920</vuln:product>
      <vuln:product>cpe:/h:lexmark:e360d</vuln:product>
      <vuln:product>cpe:/h:lexmark:x642</vuln:product>
      <vuln:product>cpe:/h:lexmark:e120</vuln:product>
      <vuln:product>cpe:/h:lexmark:x64xef</vuln:product>
      <vuln:product>cpe:/h:lexmark:w840</vuln:product>
      <vuln:product>cpe:/h:lexmark:t64x</vuln:product>
      <vuln:product>cpe:/h:lexmark:x20x</vuln:product>
      <vuln:product>cpe:/h:lexmark:x543</vuln:product>
      <vuln:product>cpe:/h:lexmark:x772e</vuln:product>
      <vuln:product>cpe:/h:lexmark:t430</vuln:product>
      <vuln:product>cpe:/h:lexmark:n70xxe</vuln:product>
      <vuln:product>cpe:/h:lexmark:e360dn</vuln:product>
      <vuln:product>cpe:/h:lexmark:c77x</vuln:product>
      <vuln:product>cpe:/h:lexmark:x26x</vuln:product>
      <vuln:product>cpe:/h:lexmark:e450</vuln:product>
      <vuln:product>cpe:/h:lexmark:c546</vuln:product>
      <vuln:product>cpe:/h:lexmark:25xxn</vuln:product>
      <vuln:product>cpe:/h:lexmark:c543</vuln:product>
      <vuln:product>cpe:/h:lexmark:x85x</vuln:product>
      <vuln:product>cpe:/h:lexmark:x644</vuln:product>
      <vuln:product>cpe:/h:lexmark:e260</vuln:product>
      <vuln:product>cpe:/h:lexmark:e460</vuln:product>
      <vuln:product>cpe:/h:lexmark:e462</vuln:product>
      <vuln:product>cpe:/h:lexmark:c52x</vuln:product>
      <vuln:product>cpe:/h:lexmark:e23x</vuln:product>
      <vuln:product>cpe:/h:lexmark:t656</vuln:product>
      <vuln:product>cpe:/h:lexmark:e34x</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0101</vuln:cve-id>
    <vuln:published-datetime>2010-05-04T12:00:35.230-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-05-07T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-05-04T14:25:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.lexmark.com/index?page=content&amp;id=TE87&amp;locale=EN&amp;userlocale=EN_US" xml:lang="en">http://support.lexmark.com/index?page=content&amp;id=TE87&amp;locale=EN&amp;userlocale=EN_US</vuln:reference>
    </vuln:references>
    <vuln:summary>The embedded HTTP server in multiple Lexmark laser and inkjet printers and MarkNet devices, including X94x, W840, T656, N4000, E462, C935dn, 25xxN, and other models, allows remote attackers to cause a denial of service (operating system halt) via a malformed HTTP Authorization header.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0103">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:energizer:duo_usb"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:energizer:duo_usb</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0103</vuln:cve-id>
    <vuln:published-datetime>2010-03-10T15:13:02.667-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-10T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-10T17:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/154421" xml:lang="en">VU#154421</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.symantec.com/connect/blogs/trojan-found-usb-battery-charger-software" xml:lang="en">http://www.symantec.com/connect/blogs/trojan-found-usb-battery-charger-software</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38571" xml:lang="en">38571</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.marketwatch.com/story/energizer-announces-duo-charger-and-usb-charger-software-problem-2010-03-05" xml:lang="en">http://www.marketwatch.com/story/energizer-announces-duo-charger-and-usb-charger-software-problem-2010-03-05</vuln:reference>
    </vuln:references>
    <vuln:summary>UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Arucer.dll file in the %WINDIR%\system32 directory, which allows remote attackers to download arbitrary programs onto a Windows PC, and execute these programs, via a request to TCP port 7777.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:broadcom:broadcom:integrated_nic_management_firmware:1.24.0.9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_6005_small_form_factor_pc"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_6005_pro_microtower_pc"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:broadcom:broadcom:integrated_nic_management_firmware:8.0.4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_dc5700_pro_microtower_pc"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_dc5700_small_form_factor_pc"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_dc5750_microtower_pc"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_dc5750_small_form_factor_pc"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_dc5850_microtower_pc"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_dc5850_small_form_factor_pc"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_dc7600_convertible_minitower_pc"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_dc7600_ultra-slim_desktop_pc"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_dc7600_small_form_factor_pc"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_dx7200_microtower_pc"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_rp3000_point_of_sale_system"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_rp5700_point_of_sale_system"/>
          <cpe-lang:fact-ref name="cpe:/h:hp:compaq_dc7600_desktop_pc"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:broadcom:broadcom:integrated_nic_management_firmware:1.24.0.9</vuln:product>
      <vuln:product>cpe:/h:broadcom:broadcom:integrated_nic_management_firmware:8.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0104</vuln:cve-id>
    <vuln:published-datetime>2010-03-18T13:30:00.383-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-06-23T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-19T12:49:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/512705" xml:lang="en">VU#512705</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02048471" xml:lang="en">HPSBGN02511</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0631" xml:lang="en">ADV-2010-0631</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38759" xml:lang="en">38759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1023710" xml:lang="en">1023710</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39003" xml:lang="en">39003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02048471" xml:lang="en">HPSBGN02511</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Broadcom Integrated NIC Management Firmware 1.x before 1.40.0.0 and 8.x before 8.08 on the HP Small Form Factor and Microtower platforms allows remote attackers to execute arbitrary code via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0105">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0105</vuln:cve-id>
    <vuln:published-datetime>2010-04-27T11:30:01.217-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-12-10T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-04-28T13:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024723" xml:lang="en">1024723</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/39658" xml:lang="en">39658</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4435" xml:lang="en">http://support.apple.com/kb/HT4435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASONRES</vuln:source>
      <vuln:reference href="http://securityreason.com/achievement_securityalert/83" xml:lang="en">20100423 MacOS X 10.6.3 filesystem hfs Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" xml:lang="en">APPLE-SA-2010-11-10-1</vuln:reference>
    </vuln:references>
    <vuln:summary>The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 supports hard links to directories and does not prevent certain deeply nested directory structures, which allows local users to cause a denial of service (filesystem corruption) via a crafted application that calls the mkdir and link functions, related to the fsck_hfs program in the diskdev_cmds component.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0106">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.2::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.0.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.4.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.4::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.5.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.5::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.6.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.6::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.7::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mp1:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr4:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr5:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr7:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.2:mr2:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.2:mr3:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.0.359"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1000"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1007"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1008"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2000"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2001"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2010"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2011"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2020"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2021"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0:mr1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0:mr2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.0.396"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.0.401"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.394"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.400"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.401"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1:mr4"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1:mr5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1:mr7"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:client_security:3.0:mr1</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.8</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1:mr4</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0:mr2</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.2.2</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1008</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.2</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.5.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr7:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2010</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.6.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1000</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1:mr5</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.394</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.4</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr5:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.0.401</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.6</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2020</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2021</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.2.1</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2000</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.0.359</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.401</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.9</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1:mr7</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.5::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1007</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2001</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.1.1</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.2:mr2:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.3</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.5</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.7</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.7::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.400</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.6::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2011</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.0.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.4.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mp1:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.2:mr3:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.2::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr4:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.4::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.0.396</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0106</vuln:cve-id>
    <vuln:published-datetime>2010-02-19T12:30:00.660-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T23:26:55.827-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-22T08:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/56354" xml:lang="en">symantec-ondemand-dos(56354)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0410" xml:lang="en">ADV-2010-0410</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100217_00" xml:lang="en">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100217_00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023621" xml:lang="en">1023621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38219" xml:lang="en">38219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38653" xml:lang="en">38653</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/62414" xml:lang="en">62414</vuln:reference>
    </vuln:references>
    <vuln:summary>The on-demand scanning in Symantec AntiVirus 10.0.x and 10.1.x before MR9, AntiVirus 10.2.x, and Client Security 3.0.x and 3.1.x before MR9, when Tamper protection is disabled, allows remote attackers to cause a denial of service (prevention of on-demand scanning) via "specific events" that prevent the user from having read access to unspecified resources.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_360:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_360:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2006"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2008"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2006"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2008"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2021"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2020"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2011"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2010"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2002"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2001"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2000"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1009"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1008"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1007"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1001"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1000"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.0.396"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.0.401"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.396"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.400"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.401"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1:mr4"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1:mr5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1:mr6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:norton_360:2.0</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.396</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2007</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2006</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1:mr4</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1007</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2001</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2002</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1008</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1:mr6</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2006</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.400</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2010</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2008</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2011</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1000</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1009</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1:mr5</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.0.401</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2020</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2021</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_360:1.0</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2000</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.0.396</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.401</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2008</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2007</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1001</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0107</vuln:cve-id>
    <vuln:published-datetime>2010-02-23T15:30:00.467-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T23:26:56.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-24T10:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/56357" xml:lang="en">symantec-symltcom-activex-bo(56357)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0411" xml:lang="en">ADV-2010-0411</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100217_01" xml:lang="en">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100217_01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023631" xml:lang="en">1023631</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023630" xml:lang="en">1023630</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023629" xml:lang="en">1023629</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1023628" xml:lang="en">1023628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38217" xml:lang="en">38217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/509717/100/0/threaded" xml:lang="en">20100224 VUPEN Security Research - Symantec Products "SYMLTCOM.dll" Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38654" xml:lang="en">38654</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/62412" xml:lang="en">62412</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.  NOTE: this is only a vulnerability if the attacker can "masquerade as an authorized site."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.2::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.0.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.4.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.4::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.5.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.5::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.6.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.6::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.7::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mp1:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr4:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr5:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr7:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.2:mr2:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.2:mr3:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.0.359"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1000"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1007"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1008"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2000"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2001"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2010"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2011"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2020"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2021"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0:mr1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0:mr2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.0.396"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.0.401"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.394"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.400"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.401"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1:mr4"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1:mr5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1:mr7"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:client_security:3.0:mr1</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.8</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1:mr4</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0:mr2</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.2.2</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1008</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.2</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.5.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr7:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2010</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.6.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1000</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1:mr5</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.394</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.4</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr5:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.0.401</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.6</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2020</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2021</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.2.1</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2000</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.0.359</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.401</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.9</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1:mr7</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.5::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1007</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2001</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.1.1</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.2:mr2:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.3</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.5</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.7</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.7::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.400</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.6::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2011</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.0.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.4.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mp1:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.2:mr3:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.2::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr4:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.4::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.0.396</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0108</vuln:cve-id>
    <vuln:published-datetime>2010-02-19T12:30:00.690-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T23:26:56.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-22T09:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/56355" xml:lang="en">scp-cliproxy-activex-bo(56355)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0412" xml:lang="en">ADV-2010-0412</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100217_02" xml:lang="en">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100217_02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38222" xml:lang="en">38222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/509681/100/0/threaded" xml:lang="en">20100219 [DSECRG-09-039] Symantec Antivirus 10.0 ActiveX - buffer Overflow.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38651" xml:lang="en">38651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://dsecrg.com/pages/vul/show.php?id=139" xml:lang="en">http://dsecrg.com/pages/vul/show.php?id=139</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9, and 10.2.x before MR4; and Symantec Client Security 3.0.x and 3.1.x before MR9 allows remote attackers to execute arbitrary code via a long argument to the SetRemoteComputerName function.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.1.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.7::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.8::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.9::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr5:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr6:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mp1:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr4:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr7:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.2:mr2:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.2::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.2:mr3:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.6.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.6::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.5.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.5::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.4.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.4::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.0.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.1.2::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0:mr2:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0:mr1:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.2::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.3::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.9::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.8::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.2.2::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.2.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.5::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.4::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.7::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.6::corporate"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:system_center:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:system_center:10.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_central_quarantine_server:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_central_quarantine_server:3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:system_center:10.0</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.5::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_central_quarantine_server:3.6</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr6:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.2:mr2:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.5.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.1.2::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.2.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.9::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.9::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.7::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr7:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.8::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0:mr1:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.7::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0:mr2:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.6::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.6.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.0.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:system_center:10.1</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_central_quarantine_server:3.5</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.4.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.5::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mp1:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.2:mr3:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr5:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.6::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.2::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr4:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.4::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.4::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.2.2::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.8::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.2::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.3::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.1.1::corporate</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0110</vuln:cve-id>
    <vuln:published-datetime>2011-01-31T16:00:01.610-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T23:26:56.360-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.9</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-01T12:20:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64940" xml:lang="en">symantec-intel-ams2-bo(64940)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-11-032" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-11-032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-11-031" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-11-031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-11-030" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-11-030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-11-028" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-11-028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0234" xml:lang="en">ADV-2011-0234</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2011&amp;suid=20110126_00" xml:lang="en">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2011&amp;suid=20110126_00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45936" xml:lang="en">45936</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1024996" xml:lang="en">1024996</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43106" xml:lang="en">43106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43099" xml:lang="en">43099</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in Intel Alert Management System (aka AMS or AMS2), as used in Symantec AntiVirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allow remote attackers to execute arbitrary code via (1) a long string to msgsys.exe, related to the AMSSendAlertAct function in AMSLIB.dll in the Intel Alert Handler service (aka Symantec Intel Handler service); a long (2) modem string or (3) PIN number to msgsys.exe, related to pagehndl.dll in the Intel Alert Handler service; or (4) a message to msgsys.exe, related to iao.exe in the Intel Alert Originator service.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.1.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.7::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.8::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.9::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr5:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr6:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mp1:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr4:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1:mr7:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.2:mr2:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.2::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.2:mr3:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.6.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.6::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.5.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.5::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.4.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.4::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.1.0.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.1.2::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0:mr2:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0:mr1:corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.2::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.3::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.9::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.8::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.2.2::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.2.1::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.5::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.4::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.7::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus:10.0.6::corporate"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:system_center:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:system_center:10.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_central_quarantine_server:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_central_quarantine_server:3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:system_center:10.0</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.5::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_central_quarantine_server:3.6</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr6:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.2:mr2:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.5.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.1.2::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.2.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.9::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.9::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.7::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr7:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.8::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0:mr1:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.7::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0:mr2:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.6::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.6.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.0.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:system_center:10.1</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_central_quarantine_server:3.5</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.4.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.5::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mp1:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.2:mr3:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr5:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.6::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.2::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1:mr4:corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.4::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.4::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.2.2::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.1.8::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.2::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.3::corporate</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus:10.0.1.1::corporate</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0111</vuln:cve-id>
    <vuln:published-datetime>2011-01-31T16:00:03.190-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T23:26:56.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-01T13:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64943" xml:lang="en">symantec-intelams2-dos(64943)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64942" xml:lang="en">symantec-intelams2-code-execution(64942)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-11-029" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-11-029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0234" xml:lang="en">ADV-2011-0234</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2011&amp;suid=20110126_01" xml:lang="en">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2011&amp;suid=20110126_01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45935" xml:lang="en">45935</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1024997" xml:lang="en">1024997</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43106" xml:lang="en">43106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43099" xml:lang="en">43099</vuln:reference>
    </vuln:references>
    <vuln:summary>HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as used in Symantec AntiVirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allows remote attackers to execute arbitrary programs by sending msgsys.exe a UNC share pathname, which is used directly in a CreateProcessA (aka CreateProcess) call.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.13"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:8.4.15"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:im_manager:7.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.1</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.5</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.0</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.7</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.13</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.6</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.15</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.12</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.10</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.3</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:7.5</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.11</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.9</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:6.0</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:7.0</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.2</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:6.5</vuln:product>
      <vuln:product>cpe:/a:symantec:im_manager:8.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0112</vuln:cve-id>
    <vuln:published-datetime>2010-10-28T16:00:02.483-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T23:26:56.717-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-10-29T08:53:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/62806" xml:lang="en">immanager-unspecified-sql-injection(62806)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-10-226/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-10-226/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-10-225/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-10-225/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-10-224/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-10-224/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-10-223/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-10-223/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-10-222/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-10-222/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-10-221/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-10-221/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-10-220/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-10-220/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2789" xml:lang="en">ADV-2010-2789</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20101027_01" xml:lang="en">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20101027_01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024648" xml:lang="en">1024648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/44299" xml:lang="en">44299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41959" xml:lang="en">41959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/68903" xml:lang="en">68903</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/68902" xml:lang="en">68902</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/68901" xml:lang="en">68901</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in the Administrative Interface in the IIS extension in Symantec IM Manager before 8.4.16 allow remote attackers to execute arbitrary SQL commands via (1) the rdReport parameter to rdpageimlogic.aspx, related to the sGetDefinition function in rdServer.dll, and SQL statements contained within a certain report file; (2) unspecified parameters in a DetailReportGroup (aka DetailReportGroup.lgx) action to rdpageimlogic.aspx; the (3) selclause, (4) whereTrendTimeClause, (5) TrendTypeForReport, (6) whereProtocolClause, or (7) groupClause parameter in a SummaryReportGroup (aka SummaryReportGroup.lgx) action to rdpageimlogic.aspx; the (8) loginTimeStamp, (9) dbo, (10) dateDiffParam, or (11) whereClause parameter in a LoggedInUsers (aka LoggedInUSers.lgx) action to (a) rdpageimlogic.aspx or (b) rdPage.aspx; the (12) selclause, (13) whereTrendTimeClause, (14) TrendTypeForReport, (15) whereProtocolClause, or (16) groupClause parameter to rdpageimlogic.aspx; (17) the groupList parameter to IMAdminReportTrendFormRun.asp; or (18) the email parameter to IMAdminScheduleReport.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:symantec:mobile_security:1.0:beta"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:google:android"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:mobile_security:1.0:beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0113</vuln:cve-id>
    <vuln:published-datetime>2010-11-15T16:00:03.110-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T23:26:56.890-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-11-16T09:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/63294" xml:lang="en">norton-mobile-setup-information-disclosure(63294)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2982" xml:lang="en">ADV-2010-2982</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20101111_00" xml:lang="en">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20101111_00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/44767" xml:lang="en">44767</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/69253" xml:lang="en">69253</vuln:reference>
    </vuln:references>
    <vuln:summary>The Symantec Norton Mobile Security application 1.0 Beta for Android records setup details, possibly including wipe/lock credentials, in the device logs, which allows user-assisted remote attackers to obtain potentially sensitive information by leveraging the ability of a separate crafted application to read these logs.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11.0.1:mp1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11.0.2:mp2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11.0.2:mp1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11.0.3001"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11.0.4:mp1a"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11.0.4:mp2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11.0:ru5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11.0:ru6"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:endpoint_protection:11.0:ru6mp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11.0.1:mp1</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11.0.2:mp1</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11.0.4:mp2</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11.0:ru6</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11.0.4</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11.0.2</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11.0.1</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11.0.3001</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11.0.2:mp2</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11.0:ru5</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11.0.4:mp1a</vuln:product>
      <vuln:product>cpe:/a:symantec:endpoint_protection:11.0:ru6mp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0114</vuln:cve-id>
    <vuln:published-datetime>2010-12-21T20:00:02.283-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T23:26:57.077-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-12-22T08:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64118" xml:lang="en">symantec-endpoint-fwcharts-code-execution(64118)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-10-291/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-10-291/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/3252" xml:lang="en">ADV-2010-3252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20101215_00" xml:lang="en">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20101215_00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45372" xml:lang="en">45372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1024900" xml:lang="en">1024900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42643" xml:lang="en">42643</vuln:reference>
    </vuln:references>
    <vuln:summary>fw_charts.php in the reporting module in the Manager (aka SEPM) component in Symantec Endpoint Protection (SEP) 11.x before 11 RU6 MP2 allows remote attackers to bypass intended restrictions on report generation, overwrite arbitrary PHP scripts, and execute arbitrary code via a crafted request.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:symantec:web_gateway:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:symantec:web_gateway:4.5.0.325"/>
          <cpe-lang:fact-ref name="cpe:/a:symantec:web_gateway:4.5.0.326"/>
          <cpe-lang:fact-ref name="cpe:/a:symantec:web_gateway:4.5.0.327"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:symantec:web_gateway_appliance"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:web_gateway:4.5</vuln:product>
      <vuln:product>cpe:/a:symantec:web_gateway:4.5.0.327</vuln:product>
      <vuln:product>cpe:/a:symantec:web_gateway:4.5.0.326</vuln:product>
      <vuln:product>cpe:/a:symantec:web_gateway:4.5.0.325</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0115</vuln:cve-id>
    <vuln:published-datetime>2011-01-14T18:00:44.100-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T23:26:57.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-17T14:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64658" xml:lang="en">symantec-web-username-sql-injection(64658)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-11-013/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-11-013/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0088" xml:lang="en">ADV-2011-0088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2011&amp;suid=20110112_00" xml:lang="en">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2011&amp;suid=20110112_00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024958" xml:lang="en">1024958</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45742" xml:lang="en">45742</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42878" xml:lang="en">42878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70415" xml:lang="en">70415</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in login.php in the GUI management console in Symantec Web Gateway 4.5 before 4.5.0.376 allows remote attackers to execute arbitrary SQL commands via the USERNAME parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0116">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.3</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.4</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.5</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.2</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.2</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0116</vuln:cve-id>
    <vuln:published-datetime>2010-08-30T16:00:01.827-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T22:33:58.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-08-31T09:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7326" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7326" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/61420" xml:lang="en">realplayer-qcp-bo(61420)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2216" xml:lang="en">ADV-2010-2216</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024370" xml:lang="en">1024370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service.real.com/realplayer/security/08262010_player/en/" xml:lang="en">http://service.real.com/realplayer/security/08262010_player/en/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2010-3/" xml:lang="en">http://secunia.com/secunia_research/2010-3/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41154" xml:lang="en">41154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41096" xml:lang="en">41096</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7326" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7326" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows might allow remote attackers to execute arbitrary code via a crafted QCP file that triggers a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0117">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.3</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.4</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.5</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.2</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.2</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0117</vuln:cve-id>
    <vuln:published-datetime>2010-08-30T16:00:01.873-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T22:33:59.063-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-08-31T09:31:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:7169" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7169" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/61421" xml:lang="en">realplayer-yuv420-code-execution(61421)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2216" xml:lang="en">ADV-2010-2216</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024370" xml:lang="en">1024370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service.real.com/realplayer/security/08262010_player/en/" xml:lang="en">http://service.real.com/realplayer/security/08262010_player/en/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2010-5/" xml:lang="en">http://secunia.com/secunia_research/2010-5/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41154" xml:lang="en">41154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41096" xml:lang="en">41096</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:7169" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:7169" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows do not properly handle dimensions during YUV420 transformations, which might allow remote attackers to execute arbitrary code via crafted MP4 content.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:becauseinter:bournal:0.8</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.4</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.7</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:1.1</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:1.0</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.1</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.2</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.9</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:1.3</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.4.5</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.3</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:1.4</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.6</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0118</vuln:cve-id>
    <vuln:published-datetime>2010-02-24T19:30:00.390-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-12T01:37:49.293-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.3</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-25T10:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-59"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38353" xml:lang="en">38353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/509685/100/0/threaded" xml:lang="en">20100222 Secunia Research: Bournal Insecure Temporary Files Security Issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2010-6/" xml:lang="en">http://secunia.com/secunia_research/2010-6/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38814" xml:lang="en">38814</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38554" xml:lang="en">38554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036764.html" xml:lang="en">FEDORA-2010-3168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036701.html" xml:lang="en">FEDORA-2010-3221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036697.html" xml:lang="en">FEDORA-2010-3301</vuln:reference>
    </vuln:references>
    <vuln:summary>Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files associated with a --hack_the_gibson update check.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:becauseinter:bournal:1.3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:8.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:becauseinter:bournal:0.8</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.4</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.7</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:1.1</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:1.0</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.1</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.2</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.9</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:1.3</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.3</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.4.5</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:1.4</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:0.6</vuln:product>
      <vuln:product>cpe:/a:becauseinter:bournal:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0119</vuln:cve-id>
    <vuln:published-datetime>2010-02-24T19:30:00.453-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-12T01:37:49.417-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-02-25T11:31:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38352" xml:lang="en">38352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/509688/100/0/threaded" xml:lang="en">20100222 Secunia Research: Bournal ccrypt Information Disclosure Security Issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2010-7/" xml:lang="en">http://secunia.com/secunia_research/2010-7/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38814" xml:lang="en">38814</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38723" xml:lang="en">38723</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036764.html" xml:lang="en">FEDORA-2010-3168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036701.html" xml:lang="en">FEDORA-2010-3221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036697.html" xml:lang="en">FEDORA-2010-3301</vuln:reference>
    </vuln:references>
    <vuln:summary>Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "echoing."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.3</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.4</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.5</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.2</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.2</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0120</vuln:cve-id>
    <vuln:published-datetime>2010-08-30T16:00:01.920-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T22:33:59.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-08-31T09:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6807" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6807" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/61422" xml:lang="en">realplayer-qcp-audio-bo(61422)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/2216" xml:lang="en">ADV-2010-2216</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024370" xml:lang="en">1024370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service.real.com/realplayer/security/08262010_player/en/" xml:lang="en">http://service.real.com/realplayer/security/08262010_player/en/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2010-8/" xml:lang="en">http://secunia.com/secunia_research/2010-8/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41154" xml:lang="en">41154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/41096" xml:lang="en">41096</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6807" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6807" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allows remote attackers to execute arbitrary code via large size values in QCP audio content.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0121">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.1"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:12.0.0.1444"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.2.1744"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0.2.1744</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0.3</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0.4</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.5</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.2</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.5</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0.2</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:12.0.0.1444</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.3</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0.5</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.4</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0121</vuln:cve-id>
    <vuln:published-datetime>2010-12-14T11:00:02.773-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-01-19T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-12-14T11:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024861" xml:lang="en">1024861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service.real.com/realplayer/security/12102010_player/en/" xml:lang="en">http://service.real.com/realplayer/security/12102010_player/en/</vuln:reference>
    </vuln:references>
    <vuln:summary>The cook codec in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, Mac RealPlayer 11.0 through 12.0.0.1444, and Linux RealPlayer 11.0.2.1744 does not properly perform initialization, which has unspecified impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:timeclock-software:employee_timeclock_software:0.99"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:timeclock-software:employee_timeclock_software:0.99</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0122</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T09:28:25.620-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-15T13:06:30.113-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T13:05:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/56799" xml:lang="en">timeclock-auth-sql-injection(56799)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38639" xml:lang="en">38639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/509995/100/0/threaded" xml:lang="en">20100310 Secunia Research: Employee Timeclock Software SQL Injection Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/62832" xml:lang="en">62832</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/62831" xml:lang="en">62831</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2010-11/" xml:lang="en">http://secunia.com/secunia_research/2010-11/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38739" xml:lang="en">38739</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:timeclock-software:employee_timeclock_software:0.99"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:timeclock-software:employee_timeclock_software:0.99</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0123</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T09:28:25.667-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-15T14:05:37.013-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T14:05:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/56798" xml:lang="en">timeclock-database-info-disclosure(56798)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/509990/100/0/threaded" xml:lang="en">20100310 Secunia Research: Employee Timeclock Software Backup Information Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/62833" xml:lang="en">62833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2010-10/" xml:lang="en">http://secunia.com/secunia_research/2010-10/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38739" xml:lang="en">38739</vuln:reference>
    </vuln:references>
    <vuln:summary>The database backup implementation in Employee Timeclock Software 0.99 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a "semi-predictable file name."</vuln:summary>
  </entry>
  <entry id="CVE-2010-0124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:timeclock-software:employee_timeclock_software:0.99"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:timeclock-software:employee_timeclock_software:0.99</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0124</vuln:cve-id>
    <vuln:published-datetime>2010-03-15T09:28:25.700-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-15T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-03-15T14:10:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/56800" xml:lang="en">timeclock-mysqldump-info-disclosure(56800)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/38642" xml:lang="en">38642</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/509996/100/0/threaded" xml:lang="en">20100310 Secunia Research: Employee Timeclock Software "mysqldump" Password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/62830" xml:lang="en">62830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2010-12/" xml:lang="en">http://secunia.com/secunia_research/2010-12/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38739" xml:lang="en">38739</vuln:reference>
    </vuln:references>
    <vuln:summary>Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer_sp:1.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.1"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:12.0.0.1444"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:11.0.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:realnetworks:realplayer:2.1.2::enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0.3</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0.4</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.5</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.2</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:2.1.2::enterprise</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0.2</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:12.0.0.1444</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0.1</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.3</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0.5</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.1.4</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer:11.0</vuln:product>
      <vuln:product>cpe:/a:realnetworks:realplayer_sp:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0125</vuln:cve-id>
    <vuln:published-datetime>2010-12-14T11:00:02.820-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-02-17T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-12-14T11:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024861" xml:lang="en">1024861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://service.real.com/realplayer/security/12102010_player/en/" xml:lang="en">http://service.real.com/realplayer/security/12102010_player/en/</vuln:reference>
    </vuln:references>
    <vuln:summary>RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, RealPlayer Enterprise 2.1.2, and Mac RealPlayer 11.0 through 12.0.0.1444 do not properly parse spectral data in AAC files, which has unspecified impact and remote attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2010-0126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:autonomy:keyview_export_sdk:10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:autonomy:keyview_export_sdk:10.9"/>
        <cpe-lang:fact-ref name="cpe:/a:autonomy:keyview_filter_sdk:10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:autonomy:keyview_filter_sdk:10.9"/>
        <cpe-lang:fact-ref name="cpe:/a:autonomy:keyview_viewer_sdk:10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:autonomy:keyview_viewer_sdk:10.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:autonomy:keyview_export_sdk:10.4</vuln:product>
      <vuln:product>cpe:/a:autonomy:keyview_filter_sdk:10.9</vuln:product>
      <vuln:product>cpe:/a:autonomy:keyview_viewer_sdk:10.4</vuln:product>
      <vuln:product>cpe:/a:autonomy:keyview_viewer_sdk:10.9</vuln:product>
      <vuln:product>cpe:/a:autonomy:keyview_filter_sdk:10.4</vuln:product>
      <vuln:product>cpe:/a:autonomy:keyview_export_sdk:10.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-0126</vuln:cve-id>
    <vuln:published-datetime>2010-08-17T16:00:02.423-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T23:26:58.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-08-18T09:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01" xml:lang="en">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/41928" xml:lang="en">41928</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-01.ibm.com/support/docview.wss?uid=swg21440812" xml:lang="en">http://www-01.ibm.com/support/docview.wss?uid=swg21440812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2010-16/" xml:lang="en">http://secunia.com/secunia_research/2010-16/</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in an unspecified library in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute arbitrary code via a crafted compound file, as demonstrated using a Quattro Pro file, which is not properly handled by the Quattro speed reader (qpssr.dll).</vuln:summary>
  </entry>
  <entry id="CVE-2010-0127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.2.602"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.1.601"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.0.596"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.0.595"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.0.0.456"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.6.606"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:1.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:shockwave_p