<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" nvd_xml_version="2.0" pub_date="2013-05-24T06:05:35" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
  <entry id="CVE-2011-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:zaal:tgt:1.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zaal:tgt:1.0.2</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.0</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.13</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.9</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.5</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.6</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.1</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.12</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.4</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.7</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.10</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.3</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:0.9.5</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.11</vuln:product>
      <vuln:product>cpe:/a:zaal:tgt:1.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0001</vuln:cve-id>
    <vuln:published-datetime>2011-03-15T13:55:02.420-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-06T23:27:53.630-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-15T14:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=667261" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=667261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/attachment.cgi?id=473779&amp;action=diff" xml:lang="en">https://bugzilla.redhat.com/attachment.cgi?id=473779&amp;action=diff</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.wpkg.org/pipermail/stgt/2011-March/004473.html" xml:lang="en">[stgt] 20110309 [PATCH] iscsi: fix buffer overflow before login</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/66010" xml:lang="en">lstf-iscsirxhandler-dos(66010)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0636" xml:lang="en">ADV-2011-0636</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025184" xml:lang="en">1025184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46817" xml:lang="en">46817</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0332.html" xml:lang="en">RHSA-2011:0332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2209" xml:lang="en">DSA-2209</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43713" xml:lang="en">43713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43706" xml:lang="en">43706</vuln:reference>
    </vuln:references>
    <vuln:summary>Double free vulnerability in the iscsi_rx_handler function (usr/iscsi/iscsid.c) in the tgt daemon (tgtd) in Linux SCSI target framework (tgt) before 1.0.14, aka scsi-target-utils, allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown vectors related to a buffer overflow during iscsi login.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.18"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.17"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.16"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.15"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.14"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.13"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.12"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.11"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.10"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.9"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.8"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.7"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.6"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.5"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.4"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.3"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.2"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56.1"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.56"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.55"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.54.8"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.54.7"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.54.6"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.54.5"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.54.4"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.54.3"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.54.2"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.54.1"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.54"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.53.8"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.53.7"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.53.6"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.53.5"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.53.4"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.53.3"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.53.2"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.53.1"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.53"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.52.6"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.52.5"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.52.4"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.52.3"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.52.2"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.52.1"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.52"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.12"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.11"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.10"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.9"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.8"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.7-7"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.7-3"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.7"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.6"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.5"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.4"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.2"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.1-2"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51.1-1"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.51"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.50.2"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.50"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.102"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.101-2"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.101-1"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.100"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.99"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.98"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.97"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.96"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.95"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.93"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.92"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.91"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.49.90"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.31"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.30"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.25.1"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.25"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.24-4"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.24-3"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:miloslav_trmac:libuser:0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.53</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.23</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.3</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.99</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.32</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.31</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.9</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.4</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.11</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.24-4</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.6</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.2</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.54.2</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.25.1</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.8.1</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.16.1</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.10</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.17</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.1-2</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.12</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.54.3</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.98</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.8</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.95</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.92</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.21</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.2</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.29</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.9</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.53.4</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.8</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.25</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.18</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.11</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.54.6</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.53.3</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.6</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.4</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.15</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.5</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.91</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.8.2</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.2</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.7-7</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.6</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.7</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.24-3</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.52.4</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.8</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.1-1</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.55</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.54.1</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.96</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.53.2</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.53.6</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.4</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.52.6</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.7</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.30</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.54</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.7</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.54.7</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.101-2</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.54.4</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.53.8</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.26</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.12</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.54.5</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.5</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.18</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.53.5</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.13</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.50.2</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.20</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.100</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.1</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.52.1</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.93</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.97</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.10</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.27</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.53.7</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.54.8</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.5</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.51.7-3</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.14</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.53.1</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.52</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.102</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.3</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.28</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.10</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.52.3</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.9</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.50</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.52.5</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.52.2</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.16</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.101-1</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.49.90</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.11</vuln:product>
      <vuln:product>cpe:/a:miloslav_trmac:libuser:0.56.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0002</vuln:cve-id>
    <vuln:published-datetime>2011-01-22T17:00:06.677-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-02-04T01:50:11.090-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-24T10:12:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://fedorahosted.org/libuser/browser/NEWS?rev=libuser-0.57" xml:lang="en">https://fedorahosted.org/libuser/browser/NEWS?rev=libuser-0.57</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=643227" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=643227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64677" xml:lang="en">libuser-password-security-bypass(64677)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0226" xml:lang="en">ADV-2011-0226</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0201" xml:lang="en">ADV-2011-0201</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0184" xml:lang="en">ADV-2011-0184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45791" xml:lang="en">45791</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0170.html" xml:lang="en">RHSA-2011:0170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/70421" xml:lang="en">70421</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:019" xml:lang="en">MDVSA-2011:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1024960" xml:lang="en">1024960</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43047" xml:lang="en">43047</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42966" xml:lang="en">42966</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42891" xml:lang="en">42891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053378.html" xml:lang="en">FEDORA-2011-0320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053365.html" xml:lang="en">FEDORA-2011-0316</vuln:reference>
    </vuln:references>
    <vuln:summary>libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.12.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.12.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.12.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.11:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.15.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.15.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.15.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.11.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.12.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.14.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.12.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.14.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.16.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.16.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.15.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.15.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:alpha2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:alpha1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.5_r14348"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:stable_2003-08-29"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:stable_2003-11-07"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:stable_2003-11-17"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.16.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4:beta4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.8</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.11</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:beta3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4:beta2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.9</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4:beta3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.12</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.10</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.15.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.12.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.12.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.7</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.11.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:stable_2003-11-17</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.14.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.10</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.14</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.16.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:stable_2003-08-29</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.9</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.7</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.8</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:beta4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.7</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.11.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.15.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.12.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.14</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.12.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.11</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:rc4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.16.0:beta2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.11.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.8</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:rc2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.1.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.11.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.15.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.12</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.10</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.13</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4:beta1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.9</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.11:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:alpha1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.15.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.14.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4:beta6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.12.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.11</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4:beta5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.16.0:beta1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.5_r14348</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.15.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:stable_2003-11-07</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.12.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.15</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.13</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:rc3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.12</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.14.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:alpha2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0003</vuln:cve-id>
    <vuln:published-datetime>2011-01-10T22:00:05.017-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-06T23:13:39.817-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-11T14:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-January/000093.html" xml:lang="en">[MediaWiki-announce] 20110104 MediaWiki security release 1.16.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.wikimedia.org/show_bug.cgi?id=26561" xml:lang="en">https://bugzilla.wikimedia.org/show_bug.cgi?id=26561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64476" xml:lang="en">mediawiki-frames-clickjacking(64476)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0017" xml:lang="en">ADV-2011-0017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/70272" xml:lang="en">70272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2011/01/04/6" xml:lang="en">[oss-security] 20110104 (possible) CVE request: Clickjacking in Mediawiki</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2011/01/04/12" xml:lang="en">[oss-security] 20110104 Re: (possible) CVE request: Clickjacking in Mediawiki</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42810" xml:lang="en">42810</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.html" xml:lang="en">FEDORA-2011-5807</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.html" xml:lang="en">FEDORA-2011-5812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.html" xml:lang="en">FEDORA-2011-5848</vuln:reference>
    </vuln:references>
    <vuln:summary>MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.28"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.37"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.29"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.36"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.30"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.31"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.26"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.25"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.35"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.27"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.32"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.13"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.18"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.19"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.4.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.22"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.20"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.24"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.23"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.34"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.33"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.6.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.6.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:piwik:piwik:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:piwik:piwik:0.2.4</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.31</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.9</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.1.9</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.4.1</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.1.3</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.8</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.1.5</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.5.3</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.6.3</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.35</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.37</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.14</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.8</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.20</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.9</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.5.2</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.29</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.23</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.36</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.7</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.2</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.1.8</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.1.4</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.6.3:rc1</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.6.4</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.27</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.25</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.12</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.4.1:rc1</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.1.2</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.24</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.11</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.4.3</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.19</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.1.10</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.5.5</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.7</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.10</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.4:rc1</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.1</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.6.3:rc2</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.1.7</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.30</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.16</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.1.1</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.6</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.6</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.17</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.3</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.33</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.4.2</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.5</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.22</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.4:rc3</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.1.6</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:1.0</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.5.4</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.32</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.18</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.4</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.34</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.5.1</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.6.1</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.6.2</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.1</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.13</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.4.4</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.26</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.4:rc2</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.28</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.4.5</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.9.9</vuln:product>
      <vuln:product>cpe:/a:piwik:piwik:0.2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0004</vuln:cve-id>
    <vuln:published-datetime>2011-01-10T15:00:17.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-02-25T01:58:20.407-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-11T08:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://piwik.org/blog/2011/01/professional-security-audit-in-piwik/" xml:lang="en">http://piwik.org/blog/2011/01/professional-security-audit-in-piwik/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://piwik.org/blog/2011/01/piwik-1-1-security-advisory/" xml:lang="en">http://piwik.org/blog/2011/01/piwik-1-1-security-advisory/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://piwik.org/blog/2011/01/piwik-1-1-2/" xml:lang="en">http://piwik.org/blog/2011/01/piwik-1-1-2/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2011/01/06/15" xml:lang="en">[oss-security] 20110106 Re: CVE Request: Multiple XSS Vulnerabiliies &lt; Piwik 1.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2011/01/06/1" xml:lang="en">[oss-security] 20110105 CVE Request: Multiple XSS Vulnerabiliies &lt; Piwik 1.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0013" xml:lang="en">ADV-2011-0013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45659" xml:lang="en">45659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42809" xml:lang="en">42809</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70310" xml:lang="en">70310</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Piwik before 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:joomla:com_search"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla%21:1.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:joomla:joomla%21:1.0.15"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:joomla:com_search</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0005</vuln:cve-id>
    <vuln:published-datetime>2011-01-10T22:00:05.297-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-01-19T02:02:41.397-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-11T11:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://yehg.net/lab/pr0js/advisories/joomla/core/%5Bjoomla_1.0.x~15%5D_cross_site_scripting" xml:lang="en">http://yehg.net/lab/pr0js/advisories/joomla/core/[joomla_1.0.x~15]_cross_site_scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64539" xml:lang="en">joomla-ordering-xss(64539)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45679" xml:lang="en">45679</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/515590/100/0/threaded" xml:lang="en">20110107 Re: Joomla! 1.0.x ~ 1.0.15 | Cross Site Scripting (XSS) Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/515553/100/0/threaded" xml:lang="en">20110105 Joomla! 1.0.x ~ 1.0.15 | Cross Site Scripting (XSS) Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.org/files/view/97273/joomla1015-xss.txt" xml:lang="en">http://packetstormsecurity.org/files/view/97273/joomla1015-xss.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70369" xml:lang="en">70369</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the com_search module for Joomla! 1.0.x through 1.0.15 allows remote attackers to inject arbitrary web script or HTML via the ordering parameter to index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.36.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.36.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.36.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.36.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.36.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.36.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.36.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.36.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0006</vuln:cve-id>
    <vuln:published-datetime>2012-06-21T19:55:01.787-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-06-26T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-06-22T11:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/torvalds/linux/commit/867c20265459d30a01b021a9c1e81fb4c5832aa9" xml:lang="en">https://github.com/torvalds/linux/commit/867c20265459d30a01b021a9c1e81fb4c5832aa9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=867c20265459d30a01b021a9c1e81fb4c5832aa9" xml:lang="en">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=867c20265459d30a01b021a9c1e81fb4c5832aa9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=667912" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=667912</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2011/01/06/18" xml:lang="en">[oss-security] 20110106 Re: CVE Request: kernel [Re: Security review of 2.6.32.28]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37" xml:lang="en">http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37</vuln:reference>
    </vuln:references>
    <vuln:summary>The ima_lsm_rule_init function in security/integrity/ima/ima_policy.c in the Linux kernel before 2.6.37, when the Linux Security Modules (LSM) framework is disabled, allows local users to bypass Integrity Measurement Architecture (IMA) rules in opportunistic circumstances by leveraging an administrator's addition of an IMA rule for LSM.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:troglobit:pimd:2.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:troglobit:pimd:2.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0007</vuln:cve-id>
    <vuln:published-datetime>2011-01-10T22:00:05.360-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-01-20T01:46:47.580-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.3</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-11T14:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-59"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2011/01/07/3" xml:lang="en">[oss-security] 20110107 CVE Request - pimd - Insecure file creation in /var/tmp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64528" xml:lang="en">pimd-pimd-symlink(64528)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0113" xml:lang="en">ADV-2011-0113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45715" xml:lang="en">45715</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/70305" xml:lang="en">70305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2011/01/07/4" xml:lang="en">[oss-security] 20110107 Re: CVE Request - pimd - Insecure file creation in /var/tmp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2147" xml:lang="en">DSA-2147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42793" xml:lang="en">42793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42759" xml:lang="en">42759</vuln:reference>
    </vuln:references>
    <vuln:summary>pimd 2.1.5 and possibly earlier versions allows user-assisted local users to overwrite arbitrary files via a symlink attack on (1) pimd.dump when a USR1 signal is sent, or (2) pimd.cache when USR2 is sent.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9_p22"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9_p21"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9_p20"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.2p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p22"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.2p3"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.2p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.7p5"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8p3"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.7p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.7p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.7p4"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.7p3"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8p9"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8p10"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8p11"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9_p19"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8p12"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8p4"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9_p17"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8p5"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9_p18"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8p6"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8p8"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p4"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p5"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p6"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p7"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p3"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.5p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p18"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.5p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p19"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.5_p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p16"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.5_p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p17"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.5"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p23"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.4p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.4p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p20"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.4_p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p21"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.4_p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p10"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.4"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p11"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3p7"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p8"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3p6"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p9"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3p5"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p14"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3p4"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p15"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3p3"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p12"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.9p13"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p9"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8p7"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p7"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p8"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p5"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8_p12"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.7_p5"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.8"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.6"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.7"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p3"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p4"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p5"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p6"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3_p7"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.6"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.7"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.8"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.5.9"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.3b1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p6"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p5"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p4"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p3"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p7"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.4p2"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.4p3"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.4p1"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.4p4"/>
          <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.4p5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:redhat:fedora:14"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p13</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.4p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.7p5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9_p22</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p8</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.5.2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8p6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.0</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.4_p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3p4</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.5.9</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.4p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p7</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p16</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9_p18</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.4p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p21</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p12</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.4</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p4</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.7p3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.7_p5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8p10</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p4</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p15</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p7</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8p5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.4p3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.4p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p20</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.3b1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.5p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p11</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p14</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8p12</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.4p5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p18</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.7p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.4p4</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8p9</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.2p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.5_p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p17</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9_p21</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.4</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.3.1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p22</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.5.8</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8p3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3p3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p8</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p7</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.7p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3p7</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.7p4</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3p5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.2p3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.4_p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3p6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.5_p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p23</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p19</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9_p17</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8p7</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.5.7</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8p8</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3_p7</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p4</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.5.3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.2p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8p4</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p9</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p12</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8_p9</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.5.6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.3p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9p10</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9_p19</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.7</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.5p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.8p11</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.6.9_p20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0008</vuln:cve-id>
    <vuln:published-datetime>2011-01-20T14:00:07.443-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-02-04T01:50:11.650-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-21T12:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=668843" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=668843</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64965" xml:lang="en">sudo-parse-privilege-escalation(64965)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0199" xml:lang="en">ADV-2011-0199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0195" xml:lang="en">ADV-2011-0195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:018" xml:lang="en">MDVSA-2011:018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42968" xml:lang="en">42968</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053341.html" xml:lang="en">FEDORA-2011-0455</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053263.html" xml:lang="en">FEDORA-2011-0470</vuln:reference>
    </vuln:references>
    <vuln:summary>A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.  NOTE: this vulnerability exists because of a CVE-2009-0034 regression.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.8:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.8:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.8:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.9:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.1:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.1:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.8.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.7.80"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.7.85"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.7.86"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.6:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.6:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.3:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.2:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.2:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.2:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.1:pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.0:pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.6.0:pre0"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.6:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.5:pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.4:pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.4:pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.4:pre3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.4.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.1:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.2.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.10:pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.10:pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.10:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.11:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.11:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:3.0.11:rc4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:4.0.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:4.0.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:bestpractical:rt:4.0.0:rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.3:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.0:rc3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.6:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.5.1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.10</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.5</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.3:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.1:pre2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.1:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.5</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.9</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.6</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.1:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.0:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.12</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.0:rc4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.6</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.0</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.4:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.7.86</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.3:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.7.85</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.11</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.3:rc3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.2:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.14</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.1:rc4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.8:rc4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.5.3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.0:pre0</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.8:rc3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.7.1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.2:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.8</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.0:pre1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.6:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.11:rc4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.0</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:4.0.0:rc3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.4:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.5:pre1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.3:rc4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.6</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.11:rc3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.1:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.10:pre2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.5:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.1:rc3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.10:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.10:pre1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.7:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.0:rc3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.0:rc5</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.1:rc4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:4.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.11:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.1:rc5</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.5</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:4.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.2:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.2:rc4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.6:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.1:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.15</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.5:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.5.2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.3:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.7:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.0</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.6:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.2:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.1:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.9:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.5.5</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.0</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.4:pre1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.7.80</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.5.7</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.17</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.0:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.0:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.5</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.2:rc5</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.4:pre3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.5.4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.10</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.0:rc3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.3:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.6:rc3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.2:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.0:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.3:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.3:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.13</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.9</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.5</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.7</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.0:rc4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.12</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.6</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.2:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.8:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.5.6</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.7</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.0:rc6</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.5:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.7.5</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.3:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.2:rc3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.4:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.0</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.8</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.4</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.6:rc1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.7</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.2.2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.7.1</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.1:rc3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.1:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.0:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.8.0:rc3</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.5:rc2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.0.11</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.1.16</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.4.4:pre2</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.8</vuln:product>
      <vuln:product>cpe:/a:bestpractical:rt:3.6.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0009</vuln:cve-id>
    <vuln:published-datetime>2011-01-25T14:00:03.810-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-25T15:29:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=672250" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=672250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.bestpractical.com/pipermail/rt-announce/2011-January/000185.html" xml:lang="en">[rt-announce] 20110119 Security vulnerability in RT 3.0 and up</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610850" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0576" xml:lang="en">ADV-2011-0576</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0475" xml:lang="en">ADV-2011-0475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0190" xml:lang="en">ADV-2011-0190</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45959" xml:lang="en">45959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2150" xml:lang="en">DSA-2150</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43438" xml:lang="en">43438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70661" xml:lang="en">70661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054740.html" xml:lang="en">FEDORA-2011-1677</vuln:reference>
    </vuln:references>
    <vuln:summary>Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determine cleartext passwords via a brute-force attack on the database.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p2"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p3"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.3b1"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p1"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p6"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p5"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p4"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.2p7"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.4p2"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.4p3"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.4p1"/>
        <cpe-lang:fact-ref name="cpe:/a:todd_miller:sudo:1.7.4p4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.4p4</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.3b1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.4p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p4</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p5</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p2</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p7</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.2p6</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.0</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.4p3</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.4p1</vuln:product>
      <vuln:product>cpe:/a:todd_miller:sudo:1.7.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0010</vuln:cve-id>
    <vuln:published-datetime>2011-01-18T13:03:08.267-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-26T23:46:25.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-19T08:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=668879" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=668879</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sudo.ws/repos/sudo/rev/fe8a94f96542" xml:lang="en">http://www.sudo.ws/repos/sudo/rev/fe8a94f96542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.sudo.ws/repos/sudo/rev/07d1b0ce530e" xml:lang="en">http://www.sudo.ws/repos/sudo/rev/07d1b0ce530e</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2011/01/12/1" xml:lang="en">[oss-security] 20110112 Re: CVE request: sudo does not ask for password on GID changes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2011/01/11/3" xml:lang="en">[oss-security] 20110111 CVE request: sudo does not ask for password on GID changes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64636" xml:lang="en">sudo-groupid-privilege-escalation(64636)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0362" xml:lang="en">ADV-2011-0362</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0212" xml:lang="en">ADV-2011-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0199" xml:lang="en">ADV-2011-0199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0195" xml:lang="en">ADV-2011-0195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0182" xml:lang="en">ADV-2011-0182</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0089" xml:lang="en">ADV-2011-0089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1046-1" xml:lang="en">USN-1046-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sudo.ws/sudo/alerts/runas_group_pw.html" xml:lang="en">http://www.sudo.ws/sudo/alerts/runas_group_pw.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45774" xml:lang="en">45774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0599.html" xml:lang="en">RHSA-2011:0599</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/70400" xml:lang="en">70400</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:018" xml:lang="en">MDVSA-2011:018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2011&amp;m=slackware-security.593654" xml:lang="en">SSA:2011-041-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43282" xml:lang="en">43282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43068" xml:lang="en">43068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42968" xml:lang="en">42968</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42949" xml:lang="en">42949</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42886" xml:lang="en">42886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2011/01/12/3" xml:lang="en">[oss-security] 20110112 Re: CVE request: sudo does not ask for password on GID changes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" xml:lang="en">SUSE-SR:2011:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053341.html" xml:lang="en">FEDORA-2011-0455</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053263.html" xml:lang="en">FEDORA-2011-0470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=609641" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=609641</vuln:reference>
    </vuln:references>
    <vuln:summary>check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.11.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.11.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.11.0:rc0"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qemu:qemu:0.1.3</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.10.1</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.10.0</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.1.4</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.1</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.10.5</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.11.0:rc2</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.1.5</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.1.2</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.10.2</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.11.0:rc1</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.11.0:rc0</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.10.6</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.1.6</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.1.1</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.10.4</vuln:product>
      <vuln:product>cpe:/a:qemu:qemu:0.10.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0011</vuln:cve-id>
    <vuln:published-datetime>2012-06-21T11:55:05.863-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-06-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-06-21T15:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/697197" xml:lang="en">https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/697197</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/65215" xml:lang="en">qemu-vnc-security-bypass(65215)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/70992" xml:lang="en">70992</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2011/01/12/2" xml:lang="en">[oss-security] 20110112 Re: CVE request: qemu-kvm: Setting VNC password to  empty string silently disables all authentication</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2011/01/11/1" xml:lang="en">[oss-security] 20110110 Re: CVE request: qemu-kvm: Setting VNC password to  empty string silently disables all authentication</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2011/01/10/3" xml:lang="en">[oss-security] 20110110 CVE request: qemu-kvm: Setting VNC password to  empty string silently disables all authentication</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-1063-1" xml:lang="en">USN-1063-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/44393" xml:lang="en">44393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43733" xml:lang="en">43733</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43272" xml:lang="en">43272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42830" xml:lang="en">42830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2011-0345.html" xml:lang="en">RHSA-2011:0345</vuln:reference>
    </vuln:references>
    <vuln:summary>qemu-kvm before 0.11.0 disables VNC authentication when the password is cleared, which allows remote attackers to bypass authentication and establish VNC sessions.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:redhat:spice-xpi:2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:spice-xpi:2.3"/>
          <cpe-lang:fact-ref name="cpe:/a:redhat:spice-xpi:2.4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:spice-xpi:2.3</vuln:product>
      <vuln:product>cpe:/a:redhat:spice-xpi:2.2</vuln:product>
      <vuln:product>cpe:/a:redhat:spice-xpi:2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0012</vuln:cve-id>
    <vuln:published-datetime>2011-04-18T13:55:00.937-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-18T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.3</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-04-18T14:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-59"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=639869" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=639869</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0899" xml:lang="en">ADV-2011-0899</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025304" xml:lang="en">1025304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/47269" xml:lang="en">47269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0426.html" xml:lang="en">RHSA-2011:0426</vuln:reference>
    </vuln:references>
    <vuln:summary>The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows local users to overwrite arbitrary files via a symlink attack on the usbrdrctl log file, which has a predictable name.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:7.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:7.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.25"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.29"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.26"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.27"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.24"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.22"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.23"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.20"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.21"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.30"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.31"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:5.5.18</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.11</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.14</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.13</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.24</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.15</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.16</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.19</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.9</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.10</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.12</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.16</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.11</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.25</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.7</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.31</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.18</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.22</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.29</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.26</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.7</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.17</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.6</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.9</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.5</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.8</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.17</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:7.0.5</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.12</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.6</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.28</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.28</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.10</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.21</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.19</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.15</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.27</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.13</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.26</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.23</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.24</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.14</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.27</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.8</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.29</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.20</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.30</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0013</vuln:cve-id>
    <vuln:published-datetime>2011-02-18T20:00:01.557-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-11-05T23:52:42.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-21T13:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14945" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14945" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12878" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12878" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=675786" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=675786</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.30" xml:lang="en">http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.30</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/security-5.html#Fixed_in_Apache_Tomcat_5.5.32" xml:lang="en">http://tomcat.apache.org/security-5.html#Fixed_in_Apache_Tomcat_5.5.32</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0376" xml:lang="en">ADV-2011-0376</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025026" xml:lang="en">1025026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46174" xml:lang="en">46174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/516209/30/90/threaded" xml:lang="en">20110205 [SECURITY] CVE-2011-0013 Apache Tomcat Manager XSS vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-1845.html" xml:lang="en">RHSA-2011:1845</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0897.html" xml:lang="en">RHSA-2011:0897</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0896.html" xml:lang="en">RHSA-2011:0896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0791.html" xml:lang="en">RHSA-2011:0791</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:030" xml:lang="en">MDVSA-2011:030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2160" xml:lang="en">DSA-2160</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.6_%28released_14_Jan_2011%29" xml:lang="en">http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.6_(released_14_Jan_2011)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5098550.html" xml:lang="en">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5098550.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5002" xml:lang="en">http://support.apple.com/kb/HT5002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/8093" xml:lang="en">8093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/45022" xml:lang="en">45022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43192" xml:lang="en">43192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=132215163318824&amp;w=2" xml:lang="en">SSRT100627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=132215163318824&amp;w=2" xml:lang="en">HPSBUX02725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" xml:lang="en">APPLE-SA-2011-10-12-3</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12878" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12878" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8j"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8k"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8l"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8m"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8n"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8o"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8p"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8q"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0:beta2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8m</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8q</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8l</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0:beta5</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8p</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0:beta4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8n</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8j</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8o</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8k</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0014</vuln:cve-id>
    <vuln:published-datetime>2011-02-18T20:00:01.777-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-26T23:46:26.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-21T14:03:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20110208.txt" xml:lang="en">http://www.openssl.org/news/secadv_20110208.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0603" xml:lang="en">ADV-2011-0603</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0399" xml:lang="en">ADV-2011-0399</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0395" xml:lang="en">ADV-2011-0395</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0389" xml:lang="en">ADV-2011-0389</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0387" xml:lang="en">ADV-2011-0387</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0361" xml:lang="en">ADV-2011-0361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1064-1" xml:lang="en">USN-1064-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025050" xml:lang="en">1025050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46264" xml:lang="en">46264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0677.html" xml:lang="en">RHSA-2011:0677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:028" xml:lang="en">MDVSA-2011:028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2162" xml:lang="en">DSA-2162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT4723" xml:lang="en">http://support.apple.com/kb/HT4723</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2011&amp;m=slackware-security.668823" xml:lang="en">SSA:2011-041-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/44269" xml:lang="en">44269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43339" xml:lang="en">43339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43301" xml:lang="en">43301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43286" xml:lang="en">43286</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43227" xml:lang="en">43227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70847" xml:lang="en">70847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=131042179515633&amp;w=2" xml:lang="en">HPSBUX02689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=131042179515633&amp;w=2" xml:lang="en">SSRT100494</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054007.html" xml:lang="en">FEDORA-2011-1273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" xml:lang="en">APPLE-SA-2011-06-23-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02794777" xml:lang="en">HPSBMA02658</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02794777" xml:lang="en">SSRT100413</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2011-002.txt.asc" xml:lang="en">NetBSD-SA2011-002</vuln:reference>
    </vuln:references>
    <vuln:summary>ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.10:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.11:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.12:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.23"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.24"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.25"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.26"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.27"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.28"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.3:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.8:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.9:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.31:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.31"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.30"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.29:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.32:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.33"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.28:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.24:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.25:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.22:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.23:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.30:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.26:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.27:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.17:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.16:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.34:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.15:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.14:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.21:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.20:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.19:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.18:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.9:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.8:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.13:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.12:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.11:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.10:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.3:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.13"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.8:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.3:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.31"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.30"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.19"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.18"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.25"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.26"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.23"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.1:alpha-cvs"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.9:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.8:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.3:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.10:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre27"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre26"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre25"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre21"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre22"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre23"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre24"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre17"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre18"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre19"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre20"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre13"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre14"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre15"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre16"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.11:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.12:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.13:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.14:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.3:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.8:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.9:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.10:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.19:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.16:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.15:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.18:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.17:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.20:alpha"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tor:tor:0.1.2.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.14:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.2:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.32:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre15</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.30:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.16</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.5:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre17</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.31:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.9:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.3:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.3:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.8.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre25</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.9:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.17</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.6</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.17</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.6:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.9:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.8:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.19</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.20:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre24</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.23:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.6.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.1:alpha-cvs</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.2:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.11:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.12:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.3:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.7</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.14</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.19</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.18</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre18</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.4</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.27</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.5:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.27:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.10</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.1:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.11</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.25:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.12</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.26</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.17</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.8:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.19:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.24:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.7.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.4:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.15</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre22</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.8</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.8:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.23</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.6:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.4:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.3</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.22:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.6</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.16:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.18</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.1:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.8</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.5</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre19</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.15</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.16:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.6</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.6:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.18</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.9:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.14</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.26:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.8</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.5</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.4</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.4:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.10:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.29</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.5</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.10</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.15</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.8</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre23</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.13:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.7:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.7:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.17:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.10:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.6</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.2:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.7:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.3</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.11:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.13</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.3</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre13</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.6:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre20</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.3</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.6.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.5</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.9</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.9</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.34:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre21</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.22</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.10:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.19:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.13</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.24</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.28:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.4:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.18:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.22</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.18:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.20</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.3:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.4</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.14:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.8:beta</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.13:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.3:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.6</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.16</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.7</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.7:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.13</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.7</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.30</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.7.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.5:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.12</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.12</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.15:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.11</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.7:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.21</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.2:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.11:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre26</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.19</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.8:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.28</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.12</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.5:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.21:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre16</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.31</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.9</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.12:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.25</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.35</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.30</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.4</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.11</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.17:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.17</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.16</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.16</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.5</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.31</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.9</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.20:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.15:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.4</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre27</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.15</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.3</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.13</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.29:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.7.3</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.5</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.10:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre14</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.10</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.5:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.12:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.26</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.23</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.25</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.21</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.4</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.20</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.33</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.14</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.7</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.6:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.14</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0015</vuln:cve-id>
    <vuln:published-datetime>2011-01-19T07:00:06.623-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-19T13:20:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLog" xml:lang="en">https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://blog.torproject.org/blog/tor-02129-released-security-patches" xml:lang="en">http://blog.torproject.org/blog/tor-02129-released-security-patches</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://archives.seul.org/or/announce/Jan-2011/msg00000.html" xml:lang="en">[or-announce] 20110117 Tor 0.2.1.29 is released (security patches)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://trac.torproject.org/projects/tor/ticket/2324" xml:lang="en">https://trac.torproject.org/projects/tor/ticket/2324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0132" xml:lang="en">ADV-2011-0132</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0131" xml:lang="en">ADV-2011-0131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024980" xml:lang="en">1024980</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45832" xml:lang="en">45832</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2011/01/18/7" xml:lang="en">[oss-security] 20110118 Re: CVE request: tor</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2148" xml:lang="en">DSA-2148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42907" xml:lang="en">42907</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42905" xml:lang="en">42905</vuln:reference>
    </vuln:references>
    <vuln:summary>Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allows remote attackers to cause a denial of service via a large compression factor.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.10:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.11:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.12:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.23"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.24"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.25"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.26"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.27"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.28"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.3:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.8:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.1.9:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.31:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.31"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.30"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.29:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.32:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.33"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.28:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.24:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.25:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.22:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.23:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.30:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.26:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.27:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.17:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.16:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.34:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.15:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.14:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.21:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.20:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.19:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.18:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.9:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.8:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.13:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.12:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.11:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.10:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.3:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.13"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.8:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.3:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.31"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.30"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.19"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.18"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.25"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.26"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.23"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.2.1:alpha-cvs"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.9:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.8:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.3:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.10:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre27"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre26"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre25"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre21"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre22"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre23"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre24"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre17"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre18"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre19"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre20"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre13"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre14"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre15"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2_pre16"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.11:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.12:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.13:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.14:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.3:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.8:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.9:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.10:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.19:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.16:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.15:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.18:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.17:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.2.2.20:alpha"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tor:tor:0.1.2.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.14:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.2:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.32:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre15</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.30:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.16</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.5:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre17</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.31:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.9:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.3:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.3:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.8.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre25</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.9:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.17</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.6</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.17</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.6:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.9:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.8:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.19</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.20:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre24</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.23:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.6.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.1:alpha-cvs</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.2:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.11:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.12:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.3:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.7</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.14</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.19</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.18</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre18</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.4</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.27</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.5:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.27:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.10</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.1:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.11</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.25:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.12</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.26</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.17</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.8:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.19:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.24:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.7.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.4:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.15</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre22</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.8</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.8:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.23</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.6:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.4:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.3</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.22:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.6</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.16:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.18</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.1:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.8</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.5</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre19</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.15</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.16:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.6</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.6:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.18</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.9:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.14</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.26:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.8</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.5</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.4</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.4:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.10:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.29</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.5</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.10</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.15</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.8</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre23</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.13:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.7:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.7:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.17:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.10:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.6</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.2:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.7:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.3</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.11:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.13</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.3</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre13</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.6:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre20</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.3</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.6.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.5</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.9</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.9</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.34:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre21</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.22</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.10:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.19:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.13</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.24</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.28:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.4:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.18:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.22</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.18:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.20</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.3:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.4</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.14:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.8:beta</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.13:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.3:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.6</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.16</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.7</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.7:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.13</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.7</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.30</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.7.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.5:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.12</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.12</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.15:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.11</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.7:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.21</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.2:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.11:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre26</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.19</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.8:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.28</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.12</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.5:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.21:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre16</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.31</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.9</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.12:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.25</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.35</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.30</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.4</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.11</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.17:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.17</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.16</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.16</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.2</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.5</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.31</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.9</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.20:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.15:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.4</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre27</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.15</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.3</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.13</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.29:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.9.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.7.3</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.5</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.10:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.2_pre14</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.0.10</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.5:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.12:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.26</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.2.1</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.23</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.25</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.21</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.4</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.20</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.0.33</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.2.1.14</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.0.7</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.6:alpha</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.2.14</vuln:product>
      <vuln:product>cpe:/a:tor:tor:0.1.1.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0016</vuln:cve-id>
    <vuln:published-datetime>2011-01-19T07:00:19.640-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-01-22T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-19T13:22:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://blog.torproject.org/blog/tor-02129-released-security-patches" xml:lang="en">http://blog.torproject.org/blog/tor-02129-released-security-patches</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://trac.torproject.org/projects/tor/ticket/2385" xml:lang="en">https://trac.torproject.org/projects/tor/ticket/2385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://trac.torproject.org/projects/tor/ticket/2384" xml:lang="en">https://trac.torproject.org/projects/tor/ticket/2384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLog" xml:lang="en">https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0132" xml:lang="en">ADV-2011-0132</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0131" xml:lang="en">ADV-2011-0131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024980" xml:lang="en">1024980</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45832" xml:lang="en">45832</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2011/01/18/7" xml:lang="en">[oss-security] 20110118 Re: CVE request: tor</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2148" xml:lang="en">DSA-2148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42907" xml:lang="en">42907</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42905" xml:lang="en">42905</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://archives.seul.org/or/announce/Jan-2011/msg00000.html" xml:lang="en">[or-announce] 20110117 Tor 0.2.1.29 is released (security patches)</vuln:reference>
    </vuln:references>
    <vuln:summary>Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly manage key data in memory, which might allow local users to obtain sensitive information by leveraging the ability to read memory that was previously used by a different process.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.51"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.50"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.44"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.43"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.34"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.33"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.31"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.30"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.64"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.63"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.62"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.61"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.60"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.54"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.53"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.52"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.23"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.24"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.21"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.22"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.42"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.65"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.66"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.67"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.68"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.41"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.40"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.32"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.20"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.14"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.05"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.04"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.03"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.02"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.01"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.00"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.36"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.35"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.34"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.33"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.32"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.31"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.30"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.22"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.21"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.03"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.02"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.01"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:3.00"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.69"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.70"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.71"/>
        <cpe-lang:fact-ref name="cpe:/a:exim:exim:4.72"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:exim:exim:4.53</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.72</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.31</vuln:product>
      <vuln:product>cpe:/a:exim:exim:2.12</vuln:product>
      <vuln:product>cpe:/a:exim:exim:2.11</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.36</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.03</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.40</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.10</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.34</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.44</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.13</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.05</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.22</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.41</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.02</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.51</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.62</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.61</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.12</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.14</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.11</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.68</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.12</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.02</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.60</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.66</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.33</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.16</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.42</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.50</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.15</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.04</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.10</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.34</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.23</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.70</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.24</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.11</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.22</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.21</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.30</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.01</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.65</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.03</vuln:product>
      <vuln:product>cpe:/a:exim:exim:2.10</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.64</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.35</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.63</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.21</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.00</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.43</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.33</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.67</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.32</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.54</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.00</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.52</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.20</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.71</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.01</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.14</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.31</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.32</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.20</vuln:product>
      <vuln:product>cpe:/a:exim:exim:4.69</vuln:product>
      <vuln:product>cpe:/a:exim:exim:3.30</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0017</vuln:cve-id>
    <vuln:published-datetime>2011-02-01T20:00:06.203-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-01T02:08:05.960-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-02T13:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-59"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.exim.org/lurker/message/20110126.034702.4d69c278.en.html" xml:lang="en">[exim-announce] 20110125 Exim 4.74 Release</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/65028" xml:lang="en">exim-openlog-privilege-escalation(65028)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0464" xml:lang="en">ADV-2011-0464</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0364" xml:lang="en">ADV-2011-0364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0245" xml:lang="en">ADV-2011-0245</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0224" xml:lang="en">ADV-2011-0224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1060-1" xml:lang="en">USN-1060-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46065" xml:lang="en">46065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2154" xml:lang="en">DSA-2154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43243" xml:lang="en">43243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43128" xml:lang="en">43128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43101" xml:lang="en">43101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70696" xml:lang="en">70696</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00004.html" xml:lang="en">SUSE-SR:2011:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.exim.org/pub/exim/ChangeLogs/ChangeLog-4.74" xml:lang="en">ftp://ftp.exim.org/pub/exim/ChangeLogs/ChangeLog-4.74</vuln:reference>
    </vuln:references>
    <vuln:summary>The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:1.0.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:1.0.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:1.0.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:1.0.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:1.0.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:1.0.0:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:1.0.0:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:1.0.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:2.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:2.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:2.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openvas:openvas_manager:1.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openvas:openvas_manager:1.0.1</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:1.0.3</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:1.0.2</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:1.0.0</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:1.0.0:beta4</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:2.0:beta2</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:1.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:1.0.0:beta6</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:1.0.0:beta7</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:1.0.0:beta1</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:1.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:1.0.0:beta5</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:2.0:beta1</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:1.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:openvas:openvas_manager:2.0:beta3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0018</vuln:cve-id>
    <vuln:published-datetime>2011-01-28T11:00:02.937-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-02-05T02:01:22.087-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-28T16:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openvas.org/OVSA20110118.html" xml:lang="en">http://www.openvas.org/OVSA20110118.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/65011" xml:lang="en">openvas-email-command-execution(65011)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0208" xml:lang="en">ADV-2011-0208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45987" xml:lang="en">45987</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/515971/100/0/threaded" xml:lang="en">20110125 [OVSA20110118] OpenVAS Manager Vulnerable To Command Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="http://www.exploit-db.com/exploits/16086" xml:lang="en">16086</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43037" xml:lang="en">43037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70639" xml:lang="en">70639</vuln:reference>
    </vuln:references>
    <vuln:summary>The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execute arbitrary commands via the (1) To or (2) From e-mail address in an OMP request to the Greenbone Security Assistant (GSA).</vuln:summary>
  </entry>
  <entry id="CVE-2011-0019">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.7.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:directory_server:8.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:directory_server:8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.7.5</vuln:product>
      <vuln:product>cpe:/a:redhat:directory_server:8.2.3</vuln:product>
      <vuln:product>cpe:/a:redhat:directory_server:8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0019</vuln:cve-id>
    <vuln:published-datetime>2011-02-23T14:00:01.670-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-30T23:28:53.783-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-23T14:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=670914" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=670914</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=666076" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=666076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025102" xml:lang="en">1025102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46489" xml:lang="en">46489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0293.html" xml:lang="en">RHSA-2011:0293</vuln:reference>
    </vuln:references>
    <vuln:summary>slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) does not properly handle simple paged result searches, which allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via multiple search requests.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.28.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.28.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.28.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.28.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.27"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.26"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.25"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.24"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.23"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:0.25"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:0.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pango:pango:1.4</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.25</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.8</vuln:product>
      <vuln:product>cpe:/a:pango:pango:0.20</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.22</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.7</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.28.2</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.15</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.1</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.23</vuln:product>
      <vuln:product>cpe:/a:pango:pango:0.21</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.28.3</vuln:product>
      <vuln:product>cpe:/a:pango:pango:0.26</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.26</vuln:product>
      <vuln:product>cpe:/a:pango:pango:0.23</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.24</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.5</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.14</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.2</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.21</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.28.0</vuln:product>
      <vuln:product>cpe:/a:pango:pango:0.22</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.27</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.9</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.3</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.28.1</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.19</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.12</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.20</vuln:product>
      <vuln:product>cpe:/a:pango:pango:0.25</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.17</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.16</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.10</vuln:product>
      <vuln:product>cpe:/a:pango:pango:0.24</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.18</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.0</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.11</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.6</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0020</vuln:cve-id>
    <vuln:published-datetime>2011-01-24T13:00:03.783-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-02-04T01:50:12.947-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-25T10:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=671122" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=671122</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.gnome.org/show_bug.cgi?id=639882" xml:lang="en">https://bugzilla.gnome.org/show_bug.cgi?id=639882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.launchpad.net/ubuntu/+source/pango1.0/+bug/696616" xml:lang="en">https://bugs.launchpad.net/ubuntu/+source/pango1.0/+bug/696616</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64832" xml:lang="en">pango-pango-bo(64832)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0238" xml:lang="en">ADV-2011-0238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0186" xml:lang="en">ADV-2011-0186</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024994" xml:lang="en">1024994</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45842" xml:lang="en">45842</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0180.html" xml:lang="en">RHSA-2011:0180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43100" xml:lang="en">43100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42934" xml:lang="en">42934</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70596" xml:lang="en">70596</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2011/01/20/2" xml:lang="en">[oss-security] 20110120 Re: CVE request: heap corruption in libpango</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2011/01/18/6" xml:lang="en">[oss-security] 20110118 CVE request: heap corruption in libpango</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.83"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.90"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.91"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.92"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.73"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.80"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.81"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.82"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.63"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.70"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.71"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.72"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.1.99i"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.1.99h"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.1.99g"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.1.99f"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.62"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.61"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.2.60"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.1.99e"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.1.99b"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.9.8a"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:1.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.0.2</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.0.3</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.1.99i</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.71</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.9.2</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.0.4</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.3.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.1.99f</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.9.6</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.1.99h</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.63</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.83</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.4.4</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.81</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.6.1</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.1.5</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.60</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.6.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.0.5</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.9.5</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.5</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.5.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.5.2</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.6</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.0.6</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.1</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.4.1</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.92</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.9.10</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.90</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.9.3</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.4.2</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.72</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.2</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.1.1</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.4</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.91</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.9.8a</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.7.2</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.6.2</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.1.99b</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.5.1</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.1.2</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.70</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.1.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.5.3</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.4.5</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.0.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.4.3</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.4.6</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.61</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.1.3</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.7.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.1.4</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.4.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.9.4</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.62</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.1.99g</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.82</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.9.9</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.73</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.2.80</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:1.0.1</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.1.99e</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0021</vuln:cve-id>
    <vuln:published-datetime>2011-01-25T14:00:04.370-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T22:42:39.173-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-25T16:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12460" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12460" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2011/01/20/3" xml:lang="en">[oss-security] 20110120 Re: CVE request: heap corruption in VLC media player</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.videolan.org/?p=vlc.git;a=commit;h=f9b664eac0e1a7bceed9d7b5854fd9fc351b4aab" xml:lang="en">http://git.videolan.org/?p=vlc.git;a=commit;h=f9b664eac0e1a7bceed9d7b5854fd9fc351b4aab</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://download.videolan.org/pub/videolan/vlc/1.1.6/vlc-1.1.6.tar.bz2" xml:lang="en">http://download.videolan.org/pub/videolan/vlc/1.1.6/vlc-1.1.6.tar.bz2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64879" xml:lang="en">vlcmediaplayer-cdg-code-execution(64879)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0185" xml:lang="en">ADV-2011-0185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45927" xml:lang="en">45927</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2011/01/19/6" xml:lang="en">[oss-security] 20110119 CVE request: heap corruption in VLC media player</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12460" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12460" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted CDG video.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.7:alpha3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.6:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.6:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.6:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.6:a4"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.6:a3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.6:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.5:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.5:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.6:a2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.8:alpha1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:389_directory_server:1.2.8:alpha2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:directory_server:8.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:directory_server:8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.5:rc4</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.6:a4</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.7.5</vuln:product>
      <vuln:product>cpe:/a:redhat:directory_server:8.2.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.6:a3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.6:rc6</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.8:alpha1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.5:rc3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.6:rc2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.5:rc2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.6:rc3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.5:rc1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.8:alpha2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.7:alpha3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.6.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.5</vuln:product>
      <vuln:product>cpe:/a:redhat:directory_server:8.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.6:rc1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.6:rc7</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.6:a2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:389_directory_server:1.2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0022</vuln:cve-id>
    <vuln:published-datetime>2011-02-23T14:00:01.813-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-30T23:28:54.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-23T15:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=671199" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=671199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025102" xml:lang="en">1025102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46489" xml:lang="en">46489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0293.html" xml:lang="en">RHSA-2011:0293</vuln:reference>
    </vuln:references>
    <vuln:summary>The setup scripts in 389 Directory Server 1.2.x (aka Red Hat Directory Server 8.2.x), when multiple unprivileged instances are configured, use 0777 permissions for the /var/run/dirsrv directory, which allows local users to cause a denial of service (daemon outage or arbitrary process termination) by replacing PID files contained in this directory.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.6"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.7"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.8"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.5"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.4"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:1.0.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.3</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.13</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.16</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.2</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.5</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.0</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.4</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.11</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.9</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.8</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.6</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.4</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.14</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.8</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.1</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.12</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.15</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.6</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.2</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.10</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.3</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:1.0.7</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.5</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0024</vuln:cve-id>
    <vuln:published-datetime>2011-03-28T12:55:03.780-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-29T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-28T13:54:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=671331" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=671331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0719" xml:lang="en">ADV-2011-0719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0370.html" xml:lang="en">RHSA-2011:0370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43821" xml:lang="en">43821</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted capture file.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:icedtea:1.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:icedtea:1.8.2</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.9.3</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.8.3</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.9.1</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.9.2</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.7</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.7.5</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.8.4</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.7.3</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.7.2</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.9</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.7.6</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.7.7</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.7.1</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.7.4</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.8</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.8.1</vuln:product>
      <vuln:product>cpe:/a:redhat:icedtea:1.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0025</vuln:cve-id>
    <vuln:published-datetime>2011-02-04T15:00:02.447-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-26T23:46:28.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-07T11:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://icedtea.classpath.org/hg/release/icedtea-web-1.0?cmd=changeset;node=3bd328e4b515" xml:lang="en">http://icedtea.classpath.org/hg/release/icedtea-web-1.0?cmd=changeset;node=3bd328e4b515</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://blog.fuseyism.com/index.php/2011/02/01/security-icedtea6-178-185-195-released/" xml:lang="en">http://blog.fuseyism.com/index.php/2011/02/01/security-icedtea6-178-185-195-released/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/65151" xml:lang="en">icedtea-jar-security-bypass(65151)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1055-1" xml:lang="en">USN-1055-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46110" xml:lang="en">46110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:054" xml:lang="en">MDVSA-2011:054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2224" xml:lang="en">DSA-2224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43135" xml:lang="en">43135</vuln:reference>
    </vuln:references>
    <vuln:summary>IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.8:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.8:sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_data_access_components:6.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_data_access_components:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.8:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.8:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0026</vuln:cve-id>
    <vuln:published-datetime>2011-01-11T20:00:01.807-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T22:42:39.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-12T11:33:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12333" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12333" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA11-011A.html" xml:lang="en">TA11-011A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-002.mspx" xml:lang="en">MS11-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-11-001/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-11-001/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0075" xml:lang="en">ADV-2011-0075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024947" xml:lang="en">1024947</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45695" xml:lang="en">45695</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/css/P8/documents/100124846" xml:lang="en">http://support.avaya.com/css/P8/documents/100124846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42804" xml:lang="en">42804</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70443" xml:lang="en">70443</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12333" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12333" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in the Data Source Name (DSN) and a crafted szDSN argument, which bypasses a signed comparison and leads to a buffer overflow, aka "DSN Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.8:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:data_access_components:2.8:sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_data_access_components:6.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_data_access_components:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.8:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:data_access_components:2.8:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0027</vuln:cve-id>
    <vuln:published-datetime>2011-01-11T20:00:01.887-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-01-21T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-12T12:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12411" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12411" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA11-011A.html" xml:lang="en">TA11-011A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-002.mspx" xml:lang="en">MS11-002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-11-002/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-11-002/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0075" xml:lang="en">ADV-2011-0075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1024947" xml:lang="en">1024947</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45698" xml:lang="en">45698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://vreugdenhilresearch.nl/ms11-002-pwn2own-heap-overflow/" xml:lang="en">http://vreugdenhilresearch.nl/ms11-002-pwn2own-heap-overflow/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/css/P8/documents/100124846" xml:lang="en">http://support.avaya.com/css/P8/documents/100124846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42804" xml:lang="en">42804</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70444" xml:lang="en">70444</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12411" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12411" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability."  NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0028</vuln:cve-id>
    <vuln:published-datetime>2011-04-13T14:55:00.923-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-04T22:51:10.597-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-04-13T18:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12301" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12301" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" xml:lang="en">TA11-102A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-033.mspx" xml:lang="en">MS11-033</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12301" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12301" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>WordPad in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse fields in Word documents, which allows remote attackers to execute arbitrary code via a crafted .doc file, aka "WordPad Converter Parsing Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:remote_desktop_connection_client:5.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:remote_desktop_connection_client:6.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:remote_desktop_connection_client:7.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:remote_desktop_connection_client:6.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:remote_desktop_connection_client:7.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:remote_desktop_connection_client:6.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:remote_desktop_connection_client:6.1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:remote_desktop_connection_client:5.2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0029</vuln:cve-id>
    <vuln:published-datetime>2011-03-09T18:00:01.793-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-04T22:51:10.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-10T08:51:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12480" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12480" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA11-067A.html" xml:lang="en">TA11-067A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-017.mspx" xml:lang="en">MS11-017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0616" xml:lang="en">ADV-2011-0616</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025172" xml:lang="en">1025172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43628" xml:lang="en">43628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/71014" xml:lang="en">71014</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12480" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12480" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Untrusted search path vulnerability in the client in Microsoft Remote Desktop Connection 5.2, 6.0, 6.1, and 7.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rdp file, aka "Remote Desktop Insecure Library Loading Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0030</vuln:cve-id>
    <vuln:published-datetime>2011-02-08T20:00:01.367-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-14T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-09T09:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12476" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12476" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-010.mspx" xml:lang="en">MS11-010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64917" xml:lang="en">ms-csrss-privilege-escalation(64917)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0323" xml:lang="en">ADV-2011-0323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025045" xml:lang="en">1025045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43250" xml:lang="en">43250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70826" xml:lang="en">70826</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12476" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12476" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Elevation of Privilege Vulnerability," a different vulnerability than CVE-2010-0023.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0031</vuln:cve-id>
    <vuln:published-datetime>2011-02-08T20:00:07.977-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-09T09:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12313" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12313" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-009.mspx" xml:lang="en">MS11-009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64919" xml:lang="en">ms-win-jscript-info-disclosure(64919)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0322" xml:lang="en">ADV-2011-0322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025044" xml:lang="en">1025044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46139" xml:lang="en">46139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43249" xml:lang="en">43249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70827" xml:lang="en">70827</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12313" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12313" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0032">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_center_tv_pack"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_center_tv_pack</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0032</vuln:cve-id>
    <vuln:published-datetime>2011-03-09T18:00:01.840-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-04T22:51:11.097-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-10T09:23:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12506" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12506" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA11-067A.html" xml:lang="en">TA11-067A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-015.mspx" xml:lang="en">MS11-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0615" xml:lang="en">ADV-2011-0615</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025170" xml:lang="en">1025170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46682" xml:lang="en">46682</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43626" xml:lang="en">43626</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/71015" xml:lang="en">71015</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12506" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12506" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Untrusted search path vulnerability in DirectShow in Microsoft Windows Vista SP1 and SP2, Windows 7 Gold and SP1, Windows Server 2008 R2 and R2 SP1, and Windows Media Center TV Pack for Windows Vista allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Digital Video Recording (.dvr-ms), Windows Recorded TV Show (.wtv), or .mpg file, aka "DirectShow Insecure Library Loading Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:-:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0033</vuln:cve-id>
    <vuln:published-datetime>2011-02-10T11:00:13.427-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T22:42:40.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-10T13:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11593" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11593" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-007.mspx" xml:lang="en">MS11-007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64906" xml:lang="en">ms-opentype-cff-code-execution(64906)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0320" xml:lang="en">ADV-2011-0320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025034" xml:lang="en">1025034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46106" xml:lang="en">46106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/css/P8/documents/100127239" xml:lang="en">http://support.avaya.com/css/P8/documents/100127239</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43252" xml:lang="en">43252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70821" xml:lang="en">70821</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11593" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11593" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The OpenType Compact Font Format (CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate parameter values in OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted font, aka "OpenType Font Encoded Character Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0034</vuln:cve-id>
    <vuln:published-datetime>2011-04-13T14:55:00.970-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-04T22:51:11.347-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-04-13T19:01:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11860" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11860" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" xml:lang="en">TA11-102A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-032.mspx" xml:lang="en">MS11-032</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11860" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11860" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Stack-based buffer overflow in the OpenType Compact Font Format (aka OTF or CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted parameter values in an OpenType font, aka "OpenType Font Stack Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0035</vuln:cve-id>
    <vuln:published-datetime>2011-02-10T11:00:13.487-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T22:42:41.220-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-10T13:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12371" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12371" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-003.mspx" xml:lang="en">MS11-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64911" xml:lang="en">ms-explorer-code-execution(64911)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0318" xml:lang="en">ADV-2011-0318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025038" xml:lang="en">1025038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46157" xml:lang="en">46157</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/css/P8/documents/100127294" xml:lang="en">http://support.avaya.com/css/P8/documents/100127294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70831" xml:lang="en">70831</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12371" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12371" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2010-2556 and CVE-2011-0036.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0036">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0036</vuln:cve-id>
    <vuln:published-datetime>2011-02-10T11:00:13.550-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-10T13:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12261" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12261" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-003.mspx" xml:lang="en">MS11-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64912" xml:lang="en">ms-explorer-code-exec(64912)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0318" xml:lang="en">ADV-2011-0318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025038" xml:lang="en">1025038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46158" xml:lang="en">46158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/css/P8/documents/100127294" xml:lang="en">http://support.avaya.com/css/P8/documents/100127294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70832" xml:lang="en">70832</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12261" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12261" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, relagted to a "dangling pointer," aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2010-2556 and CVE-2011-0035.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0037">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:malware_protection_engine:0.1.13.192"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:malware_protection_engine:1.1.3520.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:malware_protection_engine:1.1.6502.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_live_onecare"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:security_essentials"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_defender"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:forefront_client_security"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:forefront_endpoint_protection_2010"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:malicious_software_removal_tool"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_live_onecare</vuln:product>
      <vuln:product>cpe:/a:microsoft:forefront_client_security</vuln:product>
      <vuln:product>cpe:/a:microsoft:malicious_software_removal_tool</vuln:product>
      <vuln:product>cpe:/a:microsoft:malware_protection_engine:0.1.13.192</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_defender</vuln:product>
      <vuln:product>cpe:/a:microsoft:forefront_endpoint_protection_2010</vuln:product>
      <vuln:product>cpe:/a:microsoft:security_essentials</vuln:product>
      <vuln:product>cpe:/a:microsoft:malware_protection_engine:1.1.3520.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:malware_protection_engine:1.1.6502.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0037</vuln:cve-id>
    <vuln:published-datetime>2011-02-25T13:00:01.213-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-04-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-28T09:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/65626" xml:lang="en">ms-malware-engine-priv-esc(65626)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0486" xml:lang="en">ADV-2011-0486</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46540" xml:lang="en">46540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/advisory/2491888.mspx" xml:lang="en">http://www.microsoft.com/technet/security/advisory/2491888.mspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1025117" xml:lang="en">1025117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43468" xml:lang="en">43468</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0038</vuln:cve-id>
    <vuln:published-datetime>2011-02-10T11:00:13.613-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-10T13:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12270" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12270" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-003.mspx" xml:lang="en">MS11-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64913" xml:lang="en">ms-ie-dll-code-execution(64913)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0318" xml:lang="en">ADV-2011-0318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025038" xml:lang="en">1025038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46159" xml:lang="en">46159</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.fortiguard.com/advisory/FGA-2011-04.html" xml:lang="en">http://www.fortiguard.com/advisory/FGA-2011-04.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/css/P8/documents/100127294" xml:lang="en">http://support.avaya.com/css/P8/documents/100127294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70833" xml:lang="en">70833</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12270" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12270" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Untrusted search path vulnerability in Microsoft Internet Explorer 8 might allow local users to gain privileges via a Trojan horse IEShims.dll in the current working directory, as demonstrated by a Desktop directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0039</vuln:cve-id>
    <vuln:published-datetime>2011-02-08T20:00:08.070-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T22:42:41.767-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-09T10:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12537" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12537" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-014.mspx" xml:lang="en">MS11-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0327" xml:lang="en">ADV-2011-0327</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025049" xml:lang="en">1025049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46152" xml:lang="en">46152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43253" xml:lang="en">43253</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12537" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12537" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0040</vuln:cve-id>
    <vuln:published-datetime>2011-02-08T20:00:08.150-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T22:42:41.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-09T10:16:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12485" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12485" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-005.mspx" xml:lang="en">MS11-005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64915" xml:lang="en">ms-win-active-directory-dos(64915)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0319" xml:lang="en">ADV-2011-0319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025042" xml:lang="en">1025042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46145" xml:lang="en">46145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43215" xml:lang="en">43215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70825" xml:lang="en">70825</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12485" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12485" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0041">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:::x32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0041</vuln:cve-id>
    <vuln:published-datetime>2011-04-13T14:55:01.017-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-04T22:51:12.143-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-04-13T19:13:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11854" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11854" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" xml:lang="en">TA11-102A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-029.mspx" xml:lang="en">MS11-029</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11854" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11854" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF image, aka "GDI+ Integer Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x32"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_xp_media_center:2005:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_center_tv_pack"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x32"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_xp_media_center:2005:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_center_tv_pack</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:::x32</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x32</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0042</vuln:cve-id>
    <vuln:published-datetime>2011-03-09T18:00:01.857-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-04T22:51:12.287-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-10T10:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12281" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12281" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA11-067A.html" xml:lang="en">TA11-067A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-015.mspx" xml:lang="en">MS11-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0615" xml:lang="en">ADV-2011-0615</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025169" xml:lang="en">1025169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46680" xml:lang="en">46680</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43626" xml:lang="en">43626</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/71016" xml:lang="en">71016</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12281" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12281" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista does not properly parse Digital Video Recording (.dvr-ms) files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DVR-MS Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0043</vuln:cve-id>
    <vuln:published-datetime>2011-02-10T11:00:13.677-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-07-18T22:42:42.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-10T14:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12432" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12432" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-013.mspx" xml:lang="en">MS11-013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64900" xml:lang="en">ms-kerberos-checksum-privilege-escalation(64900)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0326" xml:lang="en">ADV-2011-0326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025048" xml:lang="en">1025048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46130" xml:lang="en">46130</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/css/P8/documents/100127250" xml:lang="en">http://support.avaya.com/css/P8/documents/100127250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43251" xml:lang="en">43251</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70834" xml:lang="en">70834</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12432" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12432" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unkeyed Checksum Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0045</vuln:cve-id>
    <vuln:published-datetime>2011-02-08T20:00:08.243-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-09T10:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11996" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11996" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/Bulletin/MS11-011.mspx" xml:lang="en">MS11-011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/64926" xml:lang="en">ms-win-kernel-privilege-escalation(64926)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-11-064" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-11-064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0324" xml:lang="en">ADV-2011-0324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025046" xml:lang="en">1025046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46136" xml:lang="en">46136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516276/100/0/threaded" xml:lang="en">20110208 ZDI-11-064: Microsoft Windows WmiTraceMessageVa Local Kernel Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/css/P8/documents/100127248" xml:lang="en">http://support.avaya.com/css/P8/documents/100127248</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/8110" xml:lang="en">8110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70823" xml:lang="en">70823</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11996" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11996" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The Trace Events functionality in the kernel in Microsoft Windows XP SP3 does not properly perform type conversion, which causes integer truncation and insufficient memory allocation and triggers a buffer overflow, which allows local users to gain privileges via a crafted application, related to WmiTraceMessageVa, aka "Windows Kernel Integer Truncation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.6%2B"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.19.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.19.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.19.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.21.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.21"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.21.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:4.0:rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.21</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.21.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.6%2B</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:4.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.21.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.6.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.19.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.19.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.6.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16_rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.19.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0046</vuln:cve-id>
    <vuln:published-datetime>2011-01-28T11:00:02.987-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-25T22:56:01.123-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-31T08:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=621110" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=621110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=621109" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=621109</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=621108" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=621108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=621107" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=621107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=621105" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=621105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=621090" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=621090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/65003" xml:lang="en">bugzilla-unspec-csrf(65003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0271" xml:lang="en">ADV-2011-0271</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0207" xml:lang="en">ADV-2011-0207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45982" xml:lang="en">45982</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2322" xml:lang="en">DSA-2322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.bugzilla.org/security/3.2.9/" xml:lang="en">http://www.bugzilla.org/security/3.2.9/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43165" xml:lang="en">43165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43033" xml:lang="en">43033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70710" xml:lang="en">70710</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70709" xml:lang="en">70709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70708" xml:lang="en">70708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70707" xml:lang="en">70707</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70706" xml:lang="en">70706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70705" xml:lang="en">70705</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.html" xml:lang="en">FEDORA-2011-0755</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.html" xml:lang="en">FEDORA-2011-0741</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allow remote attackers to hijack the authentication of arbitrary users for requests related to (1) adding a saved search in buglist.cgi, (2) voting in votes.cgi, (3) sanity checking in sanitycheck.cgi, (4) creating or editing a chart in chart.cgi, (5) column changing in colchange.cgi, and (6) adding, deleting, or approving a quip in quips.cgi.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.12.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.12.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.12.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.11:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.15.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.15.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.15.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.11.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.12.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.14.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.13.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.12.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.14.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.16.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.16.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.15.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.15.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:alpha2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:alpha1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.5_r14348"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:stable_2003-08-29"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:stable_2003-11-07"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:stable_2003-11-17"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.16.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.16.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4:beta4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.8</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.11</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:beta3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4:beta2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.9</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4:beta3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.12</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.16.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.10</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.15.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.12.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.12.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.7</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.11.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:stable_2003-11-17</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.14.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.10</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.14</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.16.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:stable_2003-08-29</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.9</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.7</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.8</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:beta4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.7</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.11.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.15.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.12.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.14</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.12.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.11</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:rc4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.16.0:beta2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.11.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.8</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:rc2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.1.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.11.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.15.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.12</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.10</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.13</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4:beta1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.9</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.11:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:alpha1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.15.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.14.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4:beta6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.12.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.11</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.10.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4:beta5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.16.0:beta1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.5_r14348</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.15.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:stable_2003-11-07</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.12.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.15</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.13</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:rc3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.13.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.12</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.14.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5:alpha2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0047</vuln:cve-id>
    <vuln:published-datetime>2011-02-03T20:00:05.683-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-06T23:13:44.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-04T12:05:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-February/000095.html" xml:lang="en">[MediaWiki-announce] 20110201 MediaWiki security release 1.16.2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.wikimedia.org/show_bug.cgi?id=27093" xml:lang="en">https://bugzilla.wikimedia.org/show_bug.cgi?id=27093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/65126" xml:lang="en">mediawiki-css-comments-xss(65126)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0273" xml:lang="en">ADV-2011-0273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46108" xml:lang="en">46108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43142" xml:lang="en">43142</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70770" xml:lang="en">70770</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.html" xml:lang="en">FEDORA-2011-5807</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.html" xml:lang="en">FEDORA-2011-5812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.html" xml:lang="en">FEDORA-2011-5848</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.6%2B"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.19.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.19.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.19.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.21.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.21"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.21.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.16.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.18.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.17.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:4.0:rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.21</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.21.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.6%2B</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:4.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.21.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.6.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.19.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.19.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.6.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16_rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.17.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.19.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.18.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.14.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.16.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.2.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:3.4.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0048</vuln:cve-id>
    <vuln:published-datetime>2011-01-28T11:00:03.030-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-10-25T22:56:01.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-01-31T08:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=628034" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=628034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/65005" xml:lang="en">bugzilla-url-xss(65005)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0271" xml:lang="en">ADV-2011-0271</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0207" xml:lang="en">ADV-2011-0207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/45982" xml:lang="en">45982</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2322" xml:lang="en">DSA-2322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.bugzilla.org/security/3.2.9/" xml:lang="en">http://www.bugzilla.org/security/3.2.9/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43165" xml:lang="en">43165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43033" xml:lang="en">43033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70704" xml:lang="en">70704</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.html" xml:lang="en">FEDORA-2011-0755</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.html" xml:lang="en">FEDORA-2011-0741</vuln:reference>
    </vuln:references>
    <vuln:summary>Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 creates a clickable link for a (1) javascript: or (2) data: URI in the URL (aka bug_file_loc) field, which allows remote attackers to conduct cross-site scripting (XSS) attacks against logged-out users via a crafted URI.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110130"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110129"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110128"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110127"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110126"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110125"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110124"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110123"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110122"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110121"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110120"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110119"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110118"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110117"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110116"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110115"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110114"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110113"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110112"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110111"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110110"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110109"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110108"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110107"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110106"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110105"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110104"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110103"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110102"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110101"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110115</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110126</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110113</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110109</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110129</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110106</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110128</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110114</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110110</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110119</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110111</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110112</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110108</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110103</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110120</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110122</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110116</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110124</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110102</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110125</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110117</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110118</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110127</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110121</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110104</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110105</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110123</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110130</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110101</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110107</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0049</vuln:cve-id>
    <vuln:published-datetime>2011-02-03T20:00:07.400-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-21T23:27:33.287-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-04T12:18:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/363726" xml:lang="en">VU#363726</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=628064" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=628064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=628064" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=628064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bug628064.bugzilla.mozilla.org/attachment.cgi?id=506481" xml:lang="en">https://bug628064.bugzilla.mozilla.org/attachment.cgi?id=506481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://sitewat.ch/en/Advisory/View/1" xml:lang="en">https://sitewat.ch/en/Advisory/View/1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/65113" xml:lang="en">majordomo-listfile-directory-traversal(65113)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0288" xml:lang="en">ADV-2011-0288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1025024" xml:lang="en">1025024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46127" xml:lang="en">46127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516150/100/0/threaded" xml:lang="en">20110203 Majordomo2 - Directory Traversal (SMTP/HTTP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="http://www.exploit-db.com/exploits/16103" xml:lang="en">16103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/8061" xml:lang="en">8061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43125" xml:lang="en">43125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70762" xml:lang="en">70762</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the help command, as demonstrated using (1) a crafted email and (2) cgi-bin/mj_wwwusr in the web interface.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.3_pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.3_pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.3.3_pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.3.5b"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cgiirc:cgi%3Airc:0.3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.5.1</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.3.3</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.3.4</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.3_pre1</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.3.6</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.3.1</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.4.2</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.3.3_pre1</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.5.5</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.4.3</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.4.1</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.3.5b</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.2.1</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.3.5</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.3_pre2</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.5.9</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.5.7</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.2</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.1</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.5.4</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.4</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.3</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.5.3</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.5.2</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.5</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.3.7</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.5.8</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.5.6</vuln:product>
      <vuln:product>cpe:/a:cgiirc:cgi%3Airc:0.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0050</vuln:cve-id>
    <vuln:published-datetime>2011-02-18T20:00:01.933-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-21T23:27:33.443-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-02-21T14:16:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0346" xml:lang="en">ADV-2011-0346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516328/100/0/threaded" xml:lang="en">20110209 CGI:IRC XSS issue (CVE-2011-0050)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2158" xml:lang="en">DSA-2158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://sourceforge.net/mailarchive/message.php?msg_id=27024589" xml:lang="en">[cgiirc-general] 20110207 CGI:IRC 0.5.10 released to fix XSS issue (CVE-2011-0050)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/8097" xml:lang="en">8097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43217" xml:lang="en">43217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/70844" xml:lang="en">70844</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the nonjs interface (interfaces/nonjs.pm) in CGI:IRC before 0.5.10 allows remote attackers to inject arbitrary web script or HTML via the R parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0051</vuln:cve-id>
    <vuln:published-datetime>2011-03-02T15:00:01.380-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:50.203-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-03T09:19:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14211" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14211" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=616659" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=616659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0313.html" xml:lang="en">RHSA-2011:0313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0312.html" xml:lang="en">RHSA-2011:0312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-02.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-02.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" xml:lang="en">MDVSA-2011:041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/css/P8/documents/100128655" xml:lang="en">http://support.avaya.com/css/P8/documents/100128655</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14211" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14211" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which makes it easier for remote attackers to force a user to respond positively to a dialog question, as demonstrated by a question about granting privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.21</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.22</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.23</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0053</vuln:cve-id>
    <vuln:published-datetime>2011-03-02T15:00:01.410-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:50.360-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-03T09:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14379" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14379" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=614499" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=614499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=613376" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=613376</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=605672" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=605672</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=602115" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=602115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=600974" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=600974</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=600853" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=600853</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=596232" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=596232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=576649" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=576649</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=563618" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=563618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=563243" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=563243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=558633" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=558633</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=558541" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=558541</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=558531" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=558531</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46645" xml:lang="en">46645</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0313.html" xml:lang="en">RHSA-2011:0313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0312.html" xml:lang="en">RHSA-2011:0312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-01.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:042" xml:lang="en">MDVSA-2011:042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/css/P8/documents/100128655" xml:lang="en">http://support.avaya.com/css/P8/documents/100128655</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14379" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14379" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0054</vuln:cve-id>
    <vuln:published-datetime>2011-03-02T15:00:01.490-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:50.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-03T09:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14018" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14018" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=615657" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=615657</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46648" xml:lang="en">46648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-04.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-04.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" xml:lang="en">MDVSA-2011:041</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14018" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14018" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving non-local JavaScript variables, aka an "upvarMap" issue.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0055</vuln:cve-id>
    <vuln:published-datetime>2011-03-02T15:00:01.507-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-03T10:03:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14476" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14476" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=619255" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=619255</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=616009" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=616009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-11-103/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-11-103/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46661" xml:lang="en">46661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/516802" xml:lang="en">20110302 ZDI-11-103: Mozilla Firefox JSON.stringify Dangling Pointer Remote Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-03.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-03.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" xml:lang="en">MDVSA-2011:041</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14476" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14476" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in the JSON.stringify method in js3250.dll in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via unspecified vectors related to the js_HasOwnProperty function and garbage collection.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0056</vuln:cve-id>
    <vuln:published-datetime>2011-03-02T15:00:01.537-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:50.830-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-03T10:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14013" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14013" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=622015" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=622015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46650" xml:lang="en">46650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-05.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-05.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" xml:lang="en">MDVSA-2011:041</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14013" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14013" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving exception timing and a large number of string values, aka an "atom map" issue.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0057</vuln:cve-id>
    <vuln:published-datetime>2011-03-02T15:00:01.567-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:51.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-03T10:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14200" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14200" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=626631" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=626631</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46663" xml:lang="en">46663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-06.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-06.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" xml:lang="en">MDVSA-2011:041</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14200" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14200" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in the Web Workers implementation in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to execute arbitrary code via vectors related to a JavaScript Worker and garbage collection.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0058</vuln:cve-id>
    <vuln:published-datetime>2011-03-02T15:00:01.583-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:51.157-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-03T10:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14254" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14254" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=607160" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=607160</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46660" xml:lang="en">46660</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-07.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-07.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" xml:lang="en">MDVSA-2011:041</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14254" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14254" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long string that triggers construction of a long text run.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0059</vuln:cve-id>
    <vuln:published-datetime>2011-03-02T15:00:01.597-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:51.330-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-03T11:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14473" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14473" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=573873" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=573873</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46652" xml:lang="en">46652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0313.html" xml:lang="en">RHSA-2011:0313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-10.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-10.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" xml:lang="en">MDVSA-2011:041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/css/P8/documents/100128655" xml:lang="en">http://support.avaya.com/css/P8/documents/100128655</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14473" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14473" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0061">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.22</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.21</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.23</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0061</vuln:cve-id>
    <vuln:published-datetime>2011-03-02T15:00:01.613-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:51.487-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-03T09:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14486" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14486" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=610601" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=610601</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46651" xml:lang="en">46651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-09.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-09.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:042" xml:lang="en">MDVSA-2011:042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" xml:lang="en">MDVSA-2011:041</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14486" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14486" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0062">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0062</vuln:cve-id>
    <vuln:published-datetime>2011-03-02T15:00:01.630-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:51.657-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-03T11:21:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14409" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14409" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=599610" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=599610</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=569384" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=569384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-01.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:042" xml:lang="en">MDVSA-2011:042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" xml:lang="en">MDVSA-2011:041</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14409" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14409" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.14 and Thunderbird 3.1.x before 3.1.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110101"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110102"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110103"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110104"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110105"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110106"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110107"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110108"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110110"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110109"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110112"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110111"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110114"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110113"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110116"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110115"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110118"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110117"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110120"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110119"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110122"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110121"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110124"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110123"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110130"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110129"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110126"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110125"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110128"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110127"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110131"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110201"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110202"/>
        <cpe-lang:fact-ref name="cpe:/a:mj2:majordomo_2:20110203"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110115</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110126</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110113</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110109</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110203</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110129</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110106</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110128</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110110</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110114</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110119</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110111</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110112</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110108</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110131</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110103</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110120</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110116</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110122</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110124</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110125</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110102</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110117</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110202</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110118</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110127</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110121</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110104</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110201</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110105</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110130</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110123</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110101</vuln:product>
      <vuln:product>cpe:/a:mj2:majordomo_2:20110107</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0063</vuln:cve-id>
    <vuln:published-datetime>2011-03-15T13:55:02.937-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-21T23:27:34.803-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-15T14:51:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=631307" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=631307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/66011" xml:lang="en">majordomo-listfileget-dir-traversal(66011)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/archive/1/516923/100/0/threaded" xml:lang="en">20110308 NSOADV-2011-003: Majordomo2 'help' Command Directory Traversal (Patch Bypass)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://sotiriu.de/adv/NSOADV-2011-003.txt" xml:lang="en">http://sotiriu.de/adv/NSOADV-2011-003.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/8133" xml:lang="en">8133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43631" xml:lang="en">43631</vuln:reference>
    </vuln:references>
    <vuln:summary>The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and read arbitrary files via a ./.../ sequence in the "extra" parameter to the help command, which causes the regular expression to produce .. (dot dot) sequences.  NOTE: this vulnerability is due to an incomplete fix for CVE-2011-0049.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pango:pango:1.28.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox</vuln:product>
      <vuln:product>cpe:/a:pango:pango:1.28.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0064</vuln:cve-id>
    <vuln:published-datetime>2011-03-07T16:00:01.330-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-30T23:29:03.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-03-08T09:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://build.opensuse.org/request/show/63070" xml:lang="en">https://build.opensuse.org/request/show/63070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=678563" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=678563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cgit.freedesktop.org/harfbuzz/commit/?id=a6a79df5fe2ed2cd307e7a991346faee164e70d9" xml:lang="en">http://cgit.freedesktop.org/harfbuzz/commit/?id=a6a79df5fe2ed2cd307e7a991346faee164e70d9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.novell.com/show_bug.cgi?id=672502" xml:lang="en">https://bugzilla.novell.com/show_bug.cgi?id=672502</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=606997" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=606997</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/65770" xml:lang="en">pango-hbbufferensure-bo(65770)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0683" xml:lang="en">ADV-2011-0683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0584" xml:lang="en">ADV-2011-0584</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0558" xml:lang="en">ADV-2011-0558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0555" xml:lang="en">ADV-2011-0555</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0543" xml:lang="en">ADV-2011-0543</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1082-1" xml:lang="en">USN-1082-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/46632" xml:lang="en">46632</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2011-0309.html" xml:lang="en">RHSA-2011:0309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:040" xml:lang="en">MDVSA-2011:040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2178" xml:lang="en">DSA-2178</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1025145" xml:lang="en">1025145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43800" xml:lang="en">43800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43578" xml:lang="en">43578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43572" xml:lang="en">43572</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43559" xml:lang="en">43559</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056065.html" xml:lang="en">FEDORA-2011-3194</vuln:reference>
    </vuln:references>
    <vuln:summary>The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0065</vuln:cve-id>
    <vuln:published-datetime>2011-05-07T14:55:00.997-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:52.033-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-05-09T08:31:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14142" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14142" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=634986" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=634986</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-13.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-13.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" xml:lang="en">MDVSA-2011:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2235" xml:lang="en">DSA-2235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2228" xml:lang="en">DSA-2228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2227" xml:lang="en">DSA-2227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/8340" xml:lang="en">8340</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/8331" xml:lang="en">8331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/8326" xml:lang="en">8326</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14142" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14142" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0066</vuln:cve-id>
    <vuln:published-datetime>2011-05-07T14:55:01.043-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:52.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-05-09T08:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:13970" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13970" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=634983" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=634983</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-13.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-13.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" xml:lang="en">MDVSA-2011:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2235" xml:lang="en">DSA-2235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2228" xml:lang="en">DSA-2228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2227" xml:lang="en">DSA-2227</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:13970" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:13970" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mObserverList.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0067</vuln:cve-id>
    <vuln:published-datetime>2011-05-07T14:55:01.090-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:56.627-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-05-09T08:53:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14523" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14523" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=527935" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=527935</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-14.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-14.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" xml:lang="en">MDVSA-2011:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2235" xml:lang="en">DSA-2235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2228" xml:lang="en">DSA-2228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2227" xml:lang="en">DSA-2227</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14523" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14523" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly implement autocompletion for forms, which allows remote attackers to read form history entries via a Java applet that spoofs interaction with the autocomplete controls.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.22</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.21</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.23</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0069</vuln:cve-id>
    <vuln:published-datetime>2011-05-07T14:55:01.120-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:56.783-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-05-09T09:18:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14065" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14065" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=644069" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=644069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" xml:lang="en">MDVSA-2011:080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" xml:lang="en">MDVSA-2011:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2235" xml:lang="en">DSA-2235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2228" xml:lang="en">DSA-2228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2227" xml:lang="en">DSA-2227</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14065" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14065" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0070.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0070">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0:beta12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.22</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.21</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:4.0:beta9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.23</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0070</vuln:cve-id>
    <vuln:published-datetime>2011-05-07T14:55:01.167-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:56.937-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-05-09T09:36:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14286" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14286" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=645565" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=645565</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" xml:lang="en">MDVSA-2011:080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" xml:lang="en">MDVSA-2011:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2235" xml:lang="en">DSA-2235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2228" xml:lang="en">DSA-2228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2227" xml:lang="en">DSA-2227</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14286" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14286" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0069.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.16"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.13"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.17"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.18"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.19"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.21"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.22"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.23"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.17"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.18"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.0.11"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.21</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.22</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.23</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0071</vuln:cve-id>
    <vuln:published-datetime>2011-05-07T14:55:01.197-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:57.097-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-05-09T09:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14058" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14058" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=624764" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=624764</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-16.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-16.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" xml:lang="en">MDVSA-2011:080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" xml:lang="en">MDVSA-2011:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2235" xml:lang="en">DSA-2235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2228" xml:lang="en">DSA-2228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2227" xml:lang="en">DSA-2227</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14058" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14058" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Directory traversal vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 on Windows allows remote attackers to determine the existence of arbitrary files, and possibly load resources, via vectors involving a resource: URL.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.22</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.21</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.23</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0072</vuln:cve-id>
    <vuln:published-datetime>2011-05-07T14:55:01.247-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:57.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-05-09T10:13:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14038" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14038" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=624187" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=624187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" xml:lang="en">MDVSA-2011:080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" xml:lang="en">MDVSA-2011:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2235" xml:lang="en">DSA-2235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2228" xml:lang="en">DSA-2228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2227" xml:lang="en">DSA-2227</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14038" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14038" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0074, CVE-2011-0075, CVE-2011-0077, and CVE-2011-0078.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0073</vuln:cve-id>
    <vuln:published-datetime>2011-05-07T14:55:01.293-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:57.407-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-05-09T10:26:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14020" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14020" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=630919" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=630919</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-13.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-13.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" xml:lang="en">MDVSA-2011:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2235" xml:lang="en">DSA-2235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2228" xml:lang="en">DSA-2228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2227" xml:lang="en">DSA-2227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/8310" xml:lang="en">8310</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14020" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14020" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."</vuln:summary>
  </entry>
  <entry id="CVE-2011-0074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.22</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.21</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.23</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0074</vuln:cve-id>
    <vuln:published-datetime>2011-05-07T14:55:01.323-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:57.580-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-05-09T10:27:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14317" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14317" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=619021" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=619021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" xml:lang="en">MDVSA-2011:080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" xml:lang="en">MDVSA-2011:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2235" xml:lang="en">DSA-2235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2228" xml:lang="en">DSA-2228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2227" xml:lang="en">DSA-2227</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14317" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14317" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0075, CVE-2011-0077, and CVE-2011-0078.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:2.0.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.22</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.21</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:2.0.0.23</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:3.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0075</vuln:cve-id>
    <vuln:published-datetime>2011-05-07T14:55:01.357-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-01-26T22:56:57.737-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-05-09T10:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:14086" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14086" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=635977" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=635977</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" xml:lang="en">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" xml:lang="en">MDVSA-2011:080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" xml:lang="en">MDVSA-2011:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2235" xml:lang="en">DSA-2235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2228" xml:lang="en">DSA-2228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2011/dsa-2227" xml:lang="en">DSA-2227</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:14086" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:14086" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0077, and CVE-2011-0078.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.6.16"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.18"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.17"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.19"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.0.13"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.18"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.17"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.20"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.19"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.12"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.17"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.11"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.0.15"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.14"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.16"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.13"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.10"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.17"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.18"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:3.5.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.14</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.17</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.19</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:alpha_3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.18</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.16</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.20</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.6.13</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:3.5.15</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
 