<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" nvd_xml_version="2.0" pub_date="2013-06-17T03:00:00" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
  <entry id="CVE-2013-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0:sp3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp3:tablet_pc"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp3:media_center"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0001</vuln:cve-id>
    <vuln:published-datetime>2013-01-09T13:09:37.993-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-01-16T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-09T13:20:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-004" xml:lang="en">MS13-004</vuln:reference>
    </vuln:references>
    <vuln:summary>The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unmanaged memory location, aka "System Drawing Information Disclosure Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0:sp3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp3:tablet_pc"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp3:media_center"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0002</vuln:cve-id>
    <vuln:published-datetime>2013-01-09T13:09:39.977-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T23:53:02.910-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-09T13:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" xml:lang="en">TA13-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-004" xml:lang="en">MS13-004</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memory copy operation, aka "WinForms Buffer Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0003</vuln:cve-id>
    <vuln:published-datetime>2013-01-09T13:09:40.040-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T23:53:03.393-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-09T14:16:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" xml:lang="en">TA13-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-004" xml:lang="en">MS13-004</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory copy operation, aka "S.DS.P Buffer Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0:sp3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp3:tablet_pc"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp3:media_center"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0004</vuln:cve-id>
    <vuln:published-datetime>2013-01-09T13:09:40.087-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T23:53:03.690-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-09T14:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" xml:lang="en">TA13-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-004" xml:lang="en">MS13-004</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Double Construction Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2:professional:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:-:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2:professional:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:-:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:management_odata_iis_extension:-"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:management_odata_iis_extension:-</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0005</vuln:cve-id>
    <vuln:published-datetime>2013-01-09T13:09:40.133-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T23:53:03.970-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-09T14:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" xml:lang="en">TA13-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-007" xml:lang="en">MS13-007</vuln:reference>
    </vuln:references>
    <vuln:summary>The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:6.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:6.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:5.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007:sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:word_viewer"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:expression_web:2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:expression_web::sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_server:2007:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_server:2007:sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:groove_server:2007:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:groove_server:2007:sp3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:xml_core_services:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:groove_server:2007:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:word_viewer</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x86</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2007:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:xml_core_services:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:expression_web:2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:expression_web::sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:xml_core_services:3.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2012:-</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_rt:-</vuln:product>
      <vuln:product>cpe:/a:microsoft:groove_server:2007:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:xml_core_services:5.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x86</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_server:2007:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_server:2007:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0006</vuln:cve-id>
    <vuln:published-datetime>2013-01-09T13:09:40.163-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T23:53:04.143-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-10T08:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" xml:lang="en">TA13-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-002" xml:lang="en">MS13-002</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:6.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:6.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:5.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007:sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:word_viewer"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:expression_web:2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:expression_web::sp1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_server:2007:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_server:2007:sp3"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:groove_server:2007:sp2"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:groove_server:2007:sp3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:xml_core_services:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:groove_server:2007:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/a:microsoft:word_viewer</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x86</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2007:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:xml_core_services:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:expression_web:2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:expression_web::sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:xml_core_services:3.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2012:-</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_rt:-</vuln:product>
      <vuln:product>cpe:/a:microsoft:groove_server:2007:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:xml_core_services:5.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x86</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_server:2007:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_server:2007:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0007</vuln:cve-id>
    <vuln:published-datetime>2013-01-09T13:09:40.227-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T23:53:04.317-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-10T09:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" xml:lang="en">TA13-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-002" xml:lang="en">MS13-002</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:::x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2012:-</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_rt:-</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:-:-:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0008</vuln:cve-id>
    <vuln:published-datetime>2013-01-09T13:09:40.320-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T23:53:04.567-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-10T09:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" xml:lang="en">TA13-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-005" xml:lang="en">MS13-005</vuln:reference>
    </vuln:references>
    <vuln:summary>win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:system_center_operations_manager:2007:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:system_center_operations_manager:2007:r2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:system_center_operations_manager:2007:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:system_center_operations_manager:2007:r2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0009</vuln:cve-id>
    <vuln:published-datetime>2013-01-09T13:09:40.397-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T23:53:04.767-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-10T09:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" xml:lang="en">TA13-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-003" xml:lang="en">MS13-003</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:system_center_operations_manager:2007:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:system_center_operations_manager:2007:r2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:system_center_operations_manager:2007:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:system_center_operations_manager:2007:r2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0010</vuln:cve-id>
    <vuln:published-datetime>2013-01-09T13:09:40.460-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T23:53:04.957-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-10T09:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" xml:lang="en">TA13-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-003" xml:lang="en">MS13-003</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:::x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0011</vuln:cve-id>
    <vuln:published-datetime>2013-01-09T13:09:40.493-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T23:53:05.173-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-10T10:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" xml:lang="en">TA13-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-001" xml:lang="en">MS13-001</vuln:reference>
    </vuln:references>
    <vuln:summary>The Print Spooler in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted print job, aka "Windows Print Spooler Components Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:::x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2012:-</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_rt:-</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:-:-:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0013</vuln:cve-id>
    <vuln:published-datetime>2013-01-09T13:09:40.540-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T23:53:05.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-10T10:05:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" xml:lang="en">TA13-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-006" xml:lang="en">MS13-006</vuln:reference>
    </vuln:references>
    <vuln:summary>The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to conduct SSLv2 downgrade attacks against (1) SSLv3 sessions or (2) TLS sessions by intercepting handshakes and injecting content, aka "Microsoft SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0015</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:11.697-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-13T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T12:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 6 through 9 does not properly perform auto-selection of the Shift JIS encoding, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers cross-domain scrolling events, aka "Shift JIS Character Encoding Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0018</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:11.743-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SetCapture Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0019">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0019</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:11.773-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer COmWindowProxy Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0020</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:11.820-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:51:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CMarkup Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0021</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:11.867-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T09:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer vtable Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0022</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:11.900-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer LsGetTrailInfo Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0023</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:11.947-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T09:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CDispNode Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x86</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0024</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:11.993-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T09:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer pasteHTML Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0025</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:12.040-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:13:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0026</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:12.087-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer InsertElement Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0027</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:12.117-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:20:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CPasteCommand Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:::x86</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x86</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0028</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:12.167-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:34:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CObjectElement Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0029</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:12.197-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-15T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-009" xml:lang="en">MS13-009</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CHTML Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0030</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:12.243-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-08T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T13:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-010" xml:lang="en">MS13-010</vuln:reference>
    </vuln:references>
    <vuln:summary>The Vector Markup Language (VML) implementation in Microsoft Internet Explorer 6 through 10 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via a crafted web site, aka "VML Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:-:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2:professional:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:-:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.5"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0073</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:12.290-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-13T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T13:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-015" xml:lang="en">MS13-015</vuln:reference>
    </vuln:references>
    <vuln:summary>The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "WinForms Callback Elevation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:5.0.61118.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:5.0.60401.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:5.0.60818.0:rc"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:5.0.61118.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:5.0.60401.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:5.0.60818.0:rc"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:5.0.61118.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:5.0.60401.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:5.0.60818.0:rc"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003:::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:silverlight:5.0.60818.0:rc</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:5.0.61118.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:5.0.60401.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0074</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.137-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:42.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T09:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-022" xml:lang="en">MS13-022</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:::x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2012:-</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_rt:-</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:-:-:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0075</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:12.320-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-13T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T13:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-018" xml:lang="en">MS13-018</vuln:reference>
    </vuln:references>
    <vuln:summary>The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:::x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::r2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0076</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:12.367-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-13T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T13:33:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-019" xml:lang="en">MS13-019</vuln:reference>
    </vuln:references>
    <vuln:summary>The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Reference Count Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0077</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:12.417-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-04T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T13:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-011" xml:lang="en">MS13-011</vuln:reference>
    </vuln:references>
    <vuln:summary>Quartz.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via crafted media content in (1) a media file, (2) a media stream, or (3) a Microsoft Office document, aka "Media Decompression Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_defender"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_defender</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0078</vuln:cve-id>
    <vuln:published-datetime>2013-04-09T18:55:01.063-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-10T11:01:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-034" xml:lang="en">MS13-034</vuln:reference>
    </vuln:references>
    <vuln:summary>The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.exe, which allows local users to gain privileges via a crafted application, aka "Microsoft Antimalware Improper Pathname Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio_viewer:2010:sp1:x86"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio_viewer:2010:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2010:sp1:x86"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2010:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_filter_pack:2010:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_filter_pack:2010:sp1:x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office_filter_pack:2010:sp1:x86</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2010:sp1:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio_viewer:2010:sp1:x86</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio_viewer:2010:sp1:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_filter_pack:2010:sp1:x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2010:sp1:x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0079</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.167-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:42.843-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T10:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-023" xml:lang="en">MS13-023</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_server:2010:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_foundation:2010:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:sharepoint_server:2010:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_foundation:2010:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0080</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.183-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:42.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T10:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-024" xml:lang="en">MS13-024</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_server:2010:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_foundation:2010:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:sharepoint_server:2010:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_foundation:2010:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0083</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.200-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:42.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T10:27:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-024" xml:lang="en">MS13-024</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via crafted content, leading to administrative command execution, aka "SharePoint XSS Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_server:2010:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_foundation:2010:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:sharepoint_server:2010:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_foundation:2010:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0084</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.217-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:43.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T10:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-024" xml:lang="en">MS13-024</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_server:2010:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_foundation:2010:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:sharepoint_server:2010:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_foundation:2010:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0085</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.230-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:43.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T10:33:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-024" xml:lang="en">MS13-024</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_server:2010:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:sharepoint_foundation:2010:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:sharepoint_server:2010:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:sharepoint_foundation:2010:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0086</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.247-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:43.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T10:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-025" xml:lang="en">MS13-025</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0087</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.263-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:43.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T10:36:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-021" xml:lang="en">MS13-021</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer OnResize Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0088</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.277-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:43.333-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T11:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-021" xml:lang="en">MS13-021</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer saveHistory Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0089</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.293-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:43.400-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T11:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-021" xml:lang="en">MS13-021</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CMarkupBehaviorContext Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0090">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0090</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.310-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:44.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T11:25:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-021" xml:lang="en">MS13-021</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CCaret Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0091</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.327-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:44.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T11:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-021" xml:lang="en">MS13-021</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CElement Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0092">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0092</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.357-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:44.347-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T11:31:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-021" xml:lang="en">MS13-021</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer GetMarkupPtr Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0093</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.370-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:44.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T11:33:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-021" xml:lang="en">MS13-021</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer onBeforeCopy Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:7</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_explorer:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0094</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.387-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:44.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T11:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-021" xml:lang="en">MS13-021</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer removeChild Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2008::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2011::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2011::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2008::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0095</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T20:55:01.403-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-03T23:22:44.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T11:38:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/ncas/alerts/TA13-071A" xml:lang="en">TA13-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-026" xml:lang="en">MS13-026</vuln:reference>
    </vuln:references>
    <vuln:summary>Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_essentials:2011"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_essentials:2012"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_essentials:2011</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_essentials:2012</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0096</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:33.357-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T09:26:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-045" xml:lang="en">MS13-045</vuln:reference>
    </vuln:references>
    <vuln:summary>Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:foxitsoftware:foxit_advanced_pdf_editor:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:foxitsoftware:foxit_advanced_pdf_editor:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0107</vuln:cve-id>
    <vuln:published-datetime>2013-01-26T16:55:01.007-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-01-30T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-28T10:13:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/275219" xml:lang="en">VU#275219</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Foxit Advanced PDF Editor 3 before 3.04 might allow remote attackers to execute arbitrary code via a crafted document containing instructions that reconstruct a certain security cookie.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:honeywell:enterprise_buildings_integrator:r310"/>
        <cpe-lang:fact-ref name="cpe:/a:honeywell:enterprise_buildings_integrator:r400.2"/>
        <cpe-lang:fact-ref name="cpe:/a:honeywell:enterprise_buildings_integrator:r410.1"/>
        <cpe-lang:fact-ref name="cpe:/a:honeywell:enterprise_buildings_integrator:r410.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:honeywell:symmetre:r310"/>
        <cpe-lang:fact-ref name="cpe:/a:honeywell:symmetre:r400.2"/>
        <cpe-lang:fact-ref name="cpe:/a:honeywell:symmetre:r410.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:honeywell:comfortpoint_open_manager_station:r100"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:honeywell:enterprise_buildings_integrator:r400.2</vuln:product>
      <vuln:product>cpe:/a:honeywell:symmetre:r410.1</vuln:product>
      <vuln:product>cpe:/a:honeywell:enterprise_buildings_integrator:r410.2</vuln:product>
      <vuln:product>cpe:/a:honeywell:comfortpoint_open_manager_station:r100</vuln:product>
      <vuln:product>cpe:/a:honeywell:symmetre:r310</vuln:product>
      <vuln:product>cpe:/a:honeywell:enterprise_buildings_integrator:r410.1</vuln:product>
      <vuln:product>cpe:/a:honeywell:enterprise_buildings_integrator:r310</vuln:product>
      <vuln:product>cpe:/a:honeywell:symmetre:r400.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0108</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T06:48:21.407-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T13:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/pdf/ICSA-13-053-02.pdf" xml:lang="en">http://ics-cert.us-cert.gov/pdf/ICSA-13-053-02.pdf</vuln:reference>
    </vuln:references>
    <vuln:summary>An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1, and R410.2; ComfortPoint Open Manager (aka CPO-M) Station R100; and HMIWeb Browser client packages allows remote attackers to execute arbitrary code via a crafted HTML document.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nvidia:display_driver:310.00:-:%7E%7E%7Ewindows%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:display_driver:307.00:-:%7E%7E%7Ewindows%7E%7E"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nvidia:display_driver:307.00:-:%7E%7E%7Ewindows%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:display_driver:310.00:-:%7E%7E%7Ewindows%7E%7E</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0109</vuln:cve-id>
    <vuln:published-datetime>2013-04-08T12:55:01.977-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-09T10:02:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/957036" xml:lang="en">VU#957036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nvidia.com/object/product-security.html" xml:lang="en">http://www.nvidia.com/object/product-security.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not properly handle exceptions, which allows local users to gain privileges or cause a denial of service (memory overwrite) via a crafted application.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nvidia:driver:310.00:-:%7E%7E%7Ewindows%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:driver:307.00:-:%7E%7E%7Ewindows%7E%7E"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nvidia:driver:310.00:-:%7E%7E%7Ewindows%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:driver:307.00:-:%7E%7E%7Ewindows%7E%7E</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0110</vuln:cve-id>
    <vuln:published-datetime>2013-04-08T12:55:02.010-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-09T10:19:41.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-09T10:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/957036" xml:lang="en">VU#957036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nvidia.com/object/product-security.html" xml:lang="en">http://www.nvidia.com/object/product-security.html</vuln:reference>
    </vuln:references>
    <vuln:summary>nvSCPAPISvr.exe in the NVIDIA Stereoscopic 3D Driver service, as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nvidia:driver:307.00:-:%7E%7E%7Ewindows%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:driver:310.00:-:%7E%7E%7Ewindows%7E%7E"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nvidia:driver:310.00:-:%7E%7E%7Ewindows%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:driver:307.00:-:%7E%7E%7Ewindows%7E%7E</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0111</vuln:cve-id>
    <vuln:published-datetime>2013-04-08T12:55:02.073-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-09T10:24:19.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-09T10:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/957036" xml:lang="en">VU#957036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nvidia.com/object/product-security.html" xml:lang="en">http://www.nvidia.com/object/product-security.html</vuln:reference>
    </vuln:references>
    <vuln:summary>daemonu.exe (aka the NVIDIA Update Service Daemon), as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nuance:pdf_reader:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:nuance:pdf_reader_plus:7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nuance:pdf_reader:7.0</vuln:product>
      <vuln:product>cpe:/a:nuance:pdf_reader_plus:7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0113</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T06:48:21.457-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-26T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T12:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/248449" xml:lang="en">VU#248449</vuln:reference>
    </vuln:references>
    <vuln:summary>Nuance PDF Reader 7.0 and PDF Viewer Plus 7.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cs-cart:cs-cart:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cs-cart:cs-cart:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cs-cart:cs-cart:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cs-cart:cs-cart:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cs-cart:cs-cart:3.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cs-cart:cs-cart:3.0.4</vuln:product>
      <vuln:product>cpe:/a:cs-cart:cs-cart:3.0.3</vuln:product>
      <vuln:product>cpe:/a:cs-cart:cs-cart:3.0</vuln:product>
      <vuln:product>cpe:/a:cs-cart:cs-cart:3.0.5</vuln:product>
      <vuln:product>cpe:/a:cs-cart:cs-cart:3.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0118</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T06:48:21.487-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T13:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/583564" xml:lang="en">VU#583564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/BLUU-949PQL" xml:lang="en">http://www.kb.cert.org/vuls/id/BLUU-949PQL</vuln:reference>
    </vuln:references>
    <vuln:summary>CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:dell:powerconnect_6248p:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:dell:powerconnect_6248p:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0120</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T06:48:21.533-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T13:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/160460" xml:lang="en">VU#160460</vuln:reference>
    </vuln:references>
    <vuln:summary>The web interface on Dell PowerConnect 6248P switches allows remote attackers to cause a denial of service (device crash) via a malformed request.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:avas%21t:avast%21_mobile_security:2.0.4304:-:%7E%7E%7Eandroid%7E%7E"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:avas%21t:avast%21_mobile_security:2.0.4304:-:%7E%7E%7Eandroid%7E%7E</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0122</vuln:cve-id>
    <vuln:published-datetime>2013-04-21T23:27:12.987-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-22T10:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/131263" xml:lang="en">VU#131263</vuln:reference>
    </vuln:references>
    <vuln:summary>The avast! Mobile Security application before 2.0.4400 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent to com.avast.android.mobilesecurity.app.scanner.DeleteFileActivity with zero arguments.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:askia:askiaweb:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:askia:askiaweb:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0123</vuln:cve-id>
    <vuln:published-datetime>2013-03-21T17:55:00.887-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-22T11:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/406596" xml:lang="en">VU#406596</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in the administration interface in ASKIA askiaweb allow remote attackers to execute arbitrary SQL commands via (1) the nHistoryId parameter to WebProd/pages/pgHistory.asp or (2) the OrderBy parameter to WebProd/pages/pgadmin.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:askia:askiaweb:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:askia:askiaweb:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0124</vuln:cve-id>
    <vuln:published-datetime>2013-03-21T17:55:00.910-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-22T11:51:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/406596" xml:lang="en">VU#406596</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in ASKIA askiaweb allow remote attackers to inject arbitrary web script or HTML via the (1) Number or (2) UpdatePage parameter to WebProd/cgi-bin/AskiaExt.dll.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:c2enterprise:c2_webresource:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:c2enterprise:c2_webresource:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0125</vuln:cve-id>
    <vuln:published-datetime>2013-04-04T15:55:01.150-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-05T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-05T08:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/418923" xml:lang="en">VU#418923</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in fileview.asp in C2 WebResource allows remote attackers to inject arbitrary web script or HTML via the File parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:verizon:fios_actiontec_mi424wr-gen31_router_firmware:40.19.36"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:verizon:fios_actiontec_mi424wr-gen31_router:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:verizon:fios_actiontec_mi424wr-gen31_router:-</vuln:product>
      <vuln:product>cpe:/o:verizon:fios_actiontec_mi424wr-gen31_router_firmware:40.19.36</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0126</vuln:cve-id>
    <vuln:published-datetime>2013-03-21T16:55:01.910-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-22T23:15:03.973-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-22T11:13:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/278204" xml:lang="en">VU#278204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="http://www.exploit-db.com/exploits/24860/" xml:lang="en">24860</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://infosec42.blogspot.com/2013/03/verizon-fios-router-csrf-cve-2013-0126.html" xml:lang="en">http://infosec42.blogspot.com/2013/03/verizon-fios-router-csrf-cve-2013-0126.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via the username and user_level parameters or (2) enable remote administration via the is_telnet_primary and is_telnet_secondary parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.0.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.0.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.0.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.0.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.0.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.0.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:8.5.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:9.0.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.1.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.0.2.6</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.0.2.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.3.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.1.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.0.2.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.1.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:9.0.0.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.2.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.2.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.2.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.0.2.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.0.2.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.1.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.0.2.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.3.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.0.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.1.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.3.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.0.2.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.2.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_notes:8.5.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0127</vuln:cve-id>
    <vuln:published-datetime>2013-05-01T08:00:07.730-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-01T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-01T08:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/912420" xml:lang="en">VU#912420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/83775" xml:lang="en">ibm-notes-applet-tags(83775)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-01.ibm.com/support/docview.wss?uid=swg21633819" xml:lang="en">http://www-01.ibm.com/support/docview.wss?uid=swg21633819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/fulldisclosure/2013/Apr/262" xml:lang="en">20130501 n.runs-SA-2013.005 - IBM Lotus Notes - arbitrary code execution</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote attackers to bypass intended restrictions on Java code execution and X-Confirm-Reading-To functionality via a crafted message, aka SPRs JMOY95BLM6 and JMOY95BN49.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0128">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tigertext:tigertext:3.1:-:%7E%7E%7Eiphone_os%7E%7E"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tigertext:tigertext:3.1:-:%7E%7E%7Eiphone_os%7E%7E</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0128</vuln:cve-id>
    <vuln:published-datetime>2013-04-04T15:55:01.170-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-05T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-05T09:01:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/704916" xml:lang="en">VU#704916</vuln:reference>
    </vuln:references>
    <vuln:summary>The Contact Customer Support feature in the TigerText Free Private Texting app before 3.1.402 for iOS sends a log-file e-mail message with unencrypted credentials, which allows remote attackers to obtain sensitive information by sniffing the network or leveraging access to an e-mail endpoint.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pd-admin:pd-admin:4.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pd-admin:pd-admin:4.16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0129</vuln:cve-id>
    <vuln:published-datetime>2013-04-19T07:44:10.950-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-22T08:36:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/311644" xml:lang="en">VU#311644</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.pdadmin-forum.de/thread.php?threadid=4051" xml:lang="en">http://www.pdadmin-forum.de/thread.php?threadid=4051</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in pd-admin before 4.17 allow remote authenticated users to inject arbitrary web script or HTML via (1) the WebFTP Overview "Create new directory" field or (2) the body of an e-mail autoresponder message.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0130">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:coreftp:coreftp:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:coreftp:coreftp:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0130</vuln:cve-id>
    <vuln:published-datetime>2013-03-29T13:42:29.747-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-29T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-29T13:44:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/370868" xml:lang="en">VU#370868</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.coreftp.com/forums/viewtopic.php?t=222102" xml:lang="en">http://www.coreftp.com/forums/viewtopic.php?t=222102</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Core FTP before 2.2 build 1769 allow remote FTP servers to execute arbitrary code or cause a denial of service (application crash) via a long directory name in a (1) DELE, (2) LIST, or (3) VIEW command.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:195.22:-:%7E%7Elinux_kernel%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:310.00:-:%7E%7Elinux_kernel%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:313.00:-:%7E%7Elinux_kernel%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:195.22:-:%7E%7Efreebsd%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:195.22:-:%7E%7Eesx%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:195.22:-:%7E%7Esunos%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:310.00:-:%7E%7Efreebsd%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:313.00:-:%7E%7Efreebsd%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:310.00:-:%7E%7Eesx%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:313.00:-:%7E%7Eesx%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:310.00:-:%7E%7Esunos%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:313.00:-:%7E%7Esunos%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:304.00:-:%7E%7Elinux_kernel%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:304.00:-:%7E%7Efreebsd%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:304.00:-:%7E%7Eesx%7E%7E%7E"/>
        <cpe-lang:fact-ref name="cpe:/a:nvidia:gpu_driver:304.00:-:%7E%7Esunos%7E%7E%7E"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nvidia:gpu_driver:304.00:-:%7E%7Eesx%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:310.00:-:%7E%7Efreebsd%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:195.22:-:%7E%7Elinux_kernel%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:313.00:-:%7E%7Efreebsd%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:304.00:-:%7E%7Efreebsd%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:310.00:-:%7E%7Eesx%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:313.00:-:%7E%7Eesx%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:310.00:-:%7E%7Esunos%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:313.00:-:%7E%7Esunos%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:304.00:-:%7E%7Elinux_kernel%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:304.00:-:%7E%7Esunos%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:310.00:-:%7E%7Elinux_kernel%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:195.22:-:%7E%7Esunos%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:195.22:-:%7E%7Efreebsd%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:195.22:-:%7E%7Eesx%7E%7E%7E</vuln:product>
      <vuln:product>cpe:/a:nvidia:gpu_driver:313.00:-:%7E%7Elinux_kernel%7E%7E%7E</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0131</vuln:cve-id>
    <vuln:published-datetime>2013-04-08T12:55:02.127-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-09T10:31:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/771620" xml:lang="en">VU#771620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nvidia.com/object/product-security.html" xml:lang="en">http://www.nvidia.com/object/product-security.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://nvidia.custhelp.com/app/answers/detail/a_id/3290" xml:lang="en">http://nvidia.custhelp.com/app/answers/detail/a_id/3290</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and 313.x before 313.30 for the X Window System on UNIX, when NoScanout mode is enabled, allows remote authenticated users to execute arbitrary code via a large ARGB cursor.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0132">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:parallels:parallels_plesk_panel:11.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:parallels:parallels_plesk_panel:11.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0132</vuln:cve-id>
    <vuln:published-datetime>2013-04-18T14:55:01.583-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-19T08:05:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/310500" xml:lang="en">VU#310500</vuln:reference>
    </vuln:references>
    <vuln:summary>The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to execute arbitrary PHP code via a request containing crafted environment variables.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:parallels:parallels_plesk_panel:11.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:parallels:parallels_plesk_panel:11.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0133</vuln:cve-id>
    <vuln:published-datetime>2013-04-18T14:55:03.803-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-19T08:11:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/310500" xml:lang="en">VU#310500</vuln:reference>
    </vuln:references>
    <vuln:summary>Untrusted search path vulnerability in /usr/local/psa/admin/sbin/wrapper in Parallels Plesk Panel 11.0.9 allows local users to gain privileges via a crafted PATH environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:airdroid:airdroid:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:airdroid:airdroid:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0134</vuln:cve-id>
    <vuln:published-datetime>2013-04-08T23:34:53.260-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-09T11:22:47.260-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-09T11:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/557252" xml:lang="en">VU#557252</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the web interface in AirDroid allows remote attackers to inject arbitrary web script or HTML via a crafted text message that is transmitted by a managed phone.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:chatelao:php_address_book:8.2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:chatelao:php_address_book:8.2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0135</vuln:cve-id>
    <vuln:published-datetime>2013-04-08T23:34:53.650-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-09T23:46:32.707-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-09T11:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/183692" xml:lang="en">VU#183692</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.acadion.nl/labs/advisory/20130203-phpaddressbook.html" xml:lang="en">http://www.acadion.nl/labs/advisory/20130203-phpaddressbook.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) addressbook/register/edit_user_save.php; the email parameter to (4) addressbook/register/edit_user_save.php, (5) addressbook/register/reset_password.php, (6) addressbook/register/reset_password_save.php, or (7) addressbook/register/user_add_save.php; the username parameter to (8) addressbook/register/checklogin.php or (9) addressbook/register/reset_password_save.php; the (10) lastname, (11) firstname, (12) phone, (13) permissions, or (14) notes parameter to addressbook/register/edit_user_save.php; the (15) q parameter to addressbook/register/admin_index.php; the (16) site parameter to addressbook/register/linktick.php; the (17) password parameter to addressbook/register/reset_password.php; the (18) password_hint parameter to addressbook/register/reset_password_save.php; the (19) var parameter to addressbook/register/traffic.php; or a (20) BasicLogin cookie to addressbook/register/router.php.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:mutiny:mutiny_appliance:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mutiny:mutiny_virtual_appliance:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mutiny:mutiny:5.0-1.00"/>
        <cpe-lang:fact-ref name="cpe:/a:mutiny:mutiny:5.0-1.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mutiny:mutiny_virtual_appliance:-</vuln:product>
      <vuln:product>cpe:/a:mutiny:mutiny:5.0-1.00</vuln:product>
      <vuln:product>cpe:/a:mutiny:mutiny:5.0-1.10</vuln:product>
      <vuln:product>cpe:/h:mutiny:mutiny_appliance:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0136</vuln:cve-id>
    <vuln:published-datetime>2013-06-01T10:21:05.813-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-03T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-06-03T10:36:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/701572" xml:lang="en">VU#701572</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://community.rapid7.com/community/metasploit/blog/2013/05/15/new-1day-exploits-mutiny-vulnerabilities" xml:lang="en">https://community.rapid7.com/community/metasploit/blog/2013/05/15/new-1day-exploits-mutiny-vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bitberry_software:bitzipper:2013"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bitberry_software:bitzipper:2013</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0138</vuln:cve-id>
    <vuln:published-datetime>2013-04-21T23:27:13.010-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-22T10:32:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/BLUU-95GP23" xml:lang="en">http://www.kb.cert.org/vuls/id/BLUU-95GP23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/880916" xml:lang="en">VU#880916</vuln:reference>
    </vuln:references>
    <vuln:summary>BitZipper 2013 before Update 1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ZIP archive.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:arecont:vision_av1355dn_megadome_camera:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:arecont:vision_av1355dn_megadome_camera:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0139</vuln:cve-id>
    <vuln:published-datetime>2013-04-18T14:55:03.827-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-19T08:19:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/375180" xml:lang="en">VU#375180</vuln:reference>
    </vuln:references>
    <vuln:summary>The Arecont Vision AV1355DN MegaDome camera allows remote attackers to cause a denial of service (video-capture outage) via a packet to UDP port 69.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0140">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.0:sp2a"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.5.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.6.3</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.6.1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.6.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5.1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.6.5</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.6.2</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.6.1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.5.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.5.5</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.6.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.5.3</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.5.4</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.6.4</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.5.6</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.0:sp2a</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0140</vuln:cve-id>
    <vuln:published-datetime>2013-05-01T08:00:07.827-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-01T12:47:41.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.9</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-01T08:53:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/209131" xml:lang="en">VU#209131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10042" xml:lang="en">https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10042</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication channel.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.0:sp2a"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:epolicy_orchestrator:4.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.5.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.6.3</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.6.1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.6.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5.1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5:sp1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.6.5</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.6.2</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.6.1</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.5.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.5.5</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.6.0</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.5.3</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.5.4</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.6.4</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.5.6</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:2.5</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:3.0:sp2a</vuln:product>
      <vuln:product>cpe:/a:mcafee:epolicy_orchestrator:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0141</vuln:cve-id>
    <vuln:published-datetime>2013-05-01T08:00:07.850-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-01T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-01T08:57:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/209131" xml:lang="en">VU#209131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10042" xml:lang="en">https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10042</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to upload arbitrary files via a crafted request over the Agent-Server communication channel, as demonstrated by writing to the Software/ directory.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:qnap:viostor_network_video_recorder:4.0.3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:qnap:viostor_network_video_recorder:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:qnap:nas:-"/>
        <cpe-lang:fact-ref name="cpe:/a:qnap:surveillance_station_pro:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qnap:surveillance_station_pro:-</vuln:product>
      <vuln:product>cpe:/h:qnap:viostor_network_video_recorder:-</vuln:product>
      <vuln:product>cpe:/o:qnap:viostor_network_video_recorder:4.0.3</vuln:product>
      <vuln:product>cpe:/h:qnap:nas:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0142</vuln:cve-id>
    <vuln:published-datetime>2013-06-07T16:55:01.317-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-06-10T09:03:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/927644" xml:lang="en">VU#927644</vuln:reference>
    </vuln:references>
    <vuln:summary>QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:qnap:viostor_network_video_recorder:4.0.3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:qnap:viostor_network_video_recorder:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:qnap:nas:-"/>
        <cpe-lang:fact-ref name="cpe:/a:qnap:surveillance_station_pro:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qnap:surveillance_station_pro:-</vuln:product>
      <vuln:product>cpe:/h:qnap:viostor_network_video_recorder:-</vuln:product>
      <vuln:product>cpe:/o:qnap:viostor_network_video_recorder:4.0.3</vuln:product>
      <vuln:product>cpe:/h:qnap:nas:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0143</vuln:cve-id>
    <vuln:published-datetime>2013-06-07T16:55:01.347-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-06-10T09:13:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/927644" xml:lang="en">VU#927644</vuln:reference>
    </vuln:references>
    <vuln:summary>cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0144">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:qnap:viostor_network_video_recorder:4.0.3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:qnap:viostor_network_video_recorder:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:qnap:viostor_network_video_recorder:-</vuln:product>
      <vuln:product>cpe:/o:qnap:viostor_network_video_recorder:4.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0144</vuln:cve-id>
    <vuln:published-datetime>2013-06-07T16:55:01.370-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-10T09:19:57.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-06-10T09:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/927644" xml:lang="en">VU#927644</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in cgi-bin/create_user.cgi on QNAP VioStor NVR devices with firmware 4.0.3 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts via a NEW USER action.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:vercot:serva32:2.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vercot:serva32:2.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0145</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.263-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-23T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T11:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/127108" xml:lang="en">VU#127108</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in a read request.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0148">
    <vuln:cve-id>CVE-2013-0148</vuln:cve-id>
    <vuln:published-datetime>2013-06-16T13:55:00.987-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-16T13:55:00.987-04:00</vuln:last-modified-datetime>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/900031" xml:lang="en">VU#900031</vuln:reference>
    </vuln:references>
    <vuln:summary>The Data Camouflage (aka Faircom Standard Encryption) algorithm in Faircom c-treeACE does not ensure that a decryption key is needed for accessing database contents, which allows context-dependent attackers to read cleartext database records by copying a database to another system that has a certain default configuration.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0151">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.2.0:-:%7E%7E%7E%7Ex86%7E"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.2.1:-:%7E%7E%7E%7Ex86%7E"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:xen:xen:4.2.0:-:%7E%7E%7E%7Ex86%7E</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.2.1:-:%7E%7E%7E%7Ex86%7E</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0151</vuln:cve-id>
    <vuln:published-datetime>2013-03-07T00:04:42.060-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-07T10:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=d60d7082289a74e44b3dc8f67df46c3404ca08bf" xml:lang="en">http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=d60d7082289a74e44b3dc8f67df46c3404ca08bf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2013/01/22/10" xml:lang="en">[oss-security] 20130122 Xen Security Advisory 34 (CVE-2013-0151) - nested virtualization on 32-bit exposes host crash</vuln:reference>
    </vuln:references>
    <vuln:summary>The do_hvm_op function in xen/arch/x86/hvm/hvm.c in Xen 4.2.x on the x86_32 platform does not prevent HVM_PARAM_NESTEDHVM (aka nested virtualization) operations, which allows guest OS users to cause a denial of service (long-duration page mappings and host OS crash) by leveraging administrative access to an HVM guest in a domain with a large number of VCPUs.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0152">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:xen:xen:4.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0152</vuln:cve-id>
    <vuln:published-datetime>2013-02-12T20:55:03.247-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-13T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id/1028032" xml:lang="en">1028032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/23/8" xml:lang="en">[oss-security] 20130123 Xen Security Advisory 35 (CVE-2013-0152) - Nested HVM exposes host to being driven out of memory by guest</vuln:reference>
    </vuln:references>
    <vuln:summary>Memory leak in Xen 4.2 and unstable allows local HVM guests to cause a denial of service (host memory consumption) by performing nested virtualization in a way that triggers errors that are not properly handled.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0153">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:3.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:xen:xen:4.2.0</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.2.1</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.4</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.3</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.2</vuln:product>
      <vuln:product>cpe:/o:xen:xen:3.3.0</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.1</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0153</vuln:cve-id>
    <vuln:published-datetime>2013-02-14T17:55:02.653-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-04T23:40:32.490-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-15T09:20:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/81831" xml:lang="en">xen-amdiommu-dos(81831)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57745" xml:lang="en">57745</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/05/7" xml:lang="en">[oss-security] 20130205 Xen Security Advisory 36 (CVE-2013-0153) - interrupt remap entries shared and old ones not cleared on AMD IOMMUs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2636" xml:lang="en">DSA-2636</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51881" xml:lang="en">51881</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0847.html" xml:lang="en">RHSA-2013:0847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/89867" xml:lang="en">89867</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-04/msg00052.html" xml:lang="en">openSUSE-SU-2013:0637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-04/msg00051.html" xml:lang="en">openSUSE-SU-2013:0636</vuln:reference>
    </vuln:references>
    <vuln:summary>The AMD IOMMU support in Xen 4.2.x, 4.1.x, 3.3, and other versions, when using AMD-Vi for PCI passthrough, uses the same interrupt remapping table for the host and all guests, which allows guests to cause a denial of service by injecting an interrupt into other guests.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0154">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:xen:xen:4.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0154</vuln:cve-id>
    <vuln:published-datetime>2013-01-11T23:33:49.337-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-14T23:33:51.427-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-14T13:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/80977" xml:lang="en">xen-hypercall-dos(80977)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1027937" xml:lang="en">1027937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57159" xml:lang="en">57159</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/04/2" xml:lang="en">[oss-security] 20130104 Xen Security Advisory 37 (CVE-2013-0154) - Hypervisor crash due to incorrect ASSERT (debug build only)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://seclists.org/oss-sec/2013/q1/att-17/xsa37-4_2.patch" xml:lang="en">http://seclists.org/oss-sec/2013/q1/att-17/xsa37-4_2.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/88913" xml:lang="en">88913</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-04/msg00052.html" xml:lang="en">openSUSE-SU-2013:0637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-04/msg00051.html" xml:lang="en">openSUSE-SU-2013:0636</vuln:reference>
    </vuln:references>
    <vuln:summary>The get_page_type function in xen/arch/x86/mm.c in Xen 4.2, when debugging is enabled, allows local PV or HVM guest administrators to cause a denial of service (assertion failure and hypervisor crash) via unspecified vectors related to a hypercall.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.1:pre"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.2:pre"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.12:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.13:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.10:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.17</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.1:pre</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.13</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.5:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.16</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.13:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.14</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.5:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.4:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.12</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.18</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.2:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.2:pre</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.12:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.10:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.11</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.4:rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0155</vuln:cve-id>
    <vuln:published-datetime>2013-01-13T17:55:00.900-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-05T23:24:21.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-14T13:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://groups.google.com/group/rubyonrails-security/msg/bc6f13dafe130ee9?dmode=source&amp;output=gplain" xml:lang="en">[rubyonrails-security] 20130108 Unsafe Query Generation Risk in Ruby on Rails (CVE-2013-0155)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2609" xml:lang="en">DSA-2609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5784" xml:lang="en">http://support.apple.com/kb/HT5784</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0155.html" xml:lang="en">RHSA-2013:0155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0154.html" xml:lang="en">RHSA-2013:0154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html" xml:lang="en">APPLE-SA-2013-06-04-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A</vuln:reference>
    </vuln:references>
    <vuln:summary>Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660 and CVE-2012-2694.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.0.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.0.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:rails:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.12.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.13.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.13.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.1:pre"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.2:pre"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.12:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.13:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.10:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.1.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.11.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.6.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.14</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.10.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.2.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.5.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.14.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.8.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.16</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.9.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.14</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.13.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.14.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.4:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.9.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.2.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.14.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.2.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.12</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.9.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.0.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.12.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.2:pre</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.14.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.13.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.12:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.7.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.10:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.11</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.11.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.9.4.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.0.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.17</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.1:pre</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.0.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.9.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.13</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.12.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.5:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.12</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.1.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.13:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.8.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.5.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.13</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.5:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.5.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.0.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.11</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.9.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.18</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.2:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.0.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:rails:1.2.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.9.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.5.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.10.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.6.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.1.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.4:rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0156</vuln:cve-id>
    <vuln:published-datetime>2013-01-13T17:55:00.947-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:22:30.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-14T13:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/628463" xml:lang="en">VU#628463</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/380039" xml:lang="en">VU#380039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://groups.google.com/group/rubyonrails-security/msg/c1432d0f8c70e89d?dmode=source&amp;output=gplain" xml:lang="en">[rubyonrails-security] 20130108 Multiple vulnerabilities in parameter parsing in Action Pack (CVE-2013-0156)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://community.rapid7.com/community/metasploit/blog/2013/01/09/serialization-mischief-in-ruby-land-cve-2013-0156" xml:lang="en">https://community.rapid7.com/community/metasploit/blog/2013/01/09/serialization-mischief-in-ruby-land-cve-2013-0156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.insinuator.net/2013/01/rails-yaml/" xml:lang="en">http://www.insinuator.net/2013/01/rails-yaml/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2604" xml:lang="en">DSA-2604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/" xml:lang="en">http://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0155.html" xml:lang="en">RHSA-2013:0155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0154.html" xml:lang="en">RHSA-2013:0154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0153.html" xml:lang="en">RHSA-2013:0153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html" xml:lang="en">APPLE-SA-2013-03-14-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A</vuln:reference>
    </vuln:references>
    <vuln:summary>active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0158">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.400"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.401"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.404"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.402"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.403"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.431"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.430"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.433"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.432"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.427"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.426"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.429"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.428"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.423"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.422"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.425"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.424"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.419"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.418"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.421"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.420"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.414"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.415"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.416"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.417"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.410"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.411"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.412"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.413"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.406"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.407"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.408"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.409"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.405"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.436"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.437"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.434"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.435"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.480.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.409.1::lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.409.2::lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.466.2:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.466.1:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.447.2:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.447.1:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.424.6:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.424.5:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.424.4:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.424.3:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.424.2:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.424.1:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.447:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.424:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.400:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.409.3:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.409.2:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.409.1:-:lts"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.447.1.1:-:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.447.2.2:-:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.447.3.1:-:enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.466.1.2:-:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:cloudbees:jenkins:1.466.2.1:-:enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.428</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.447.2.2:-:enterprise</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.421</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.425</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.447.1.1:-:enterprise</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.447:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.424.1:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.427</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.424:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.408</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.424.4:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.466.2.1:-:enterprise</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.436</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.416</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.430</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.419</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.424.6:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.414</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.424.3:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.415</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.410</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.418</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.431</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.422</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.424</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.466.1.2:-:enterprise</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.434</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.432</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.409.2:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.406</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.402</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.401</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.433</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.437</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.420</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.423</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.480.3.1</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.429</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.417</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.400</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.466.1:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.435</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.447.1:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.409.1::lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.400:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.424.2:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.447.2:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.409</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.409.3:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.411</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.405</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.447.3.1:-:enterprise</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.404</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.466.2:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.407</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.424.5:-:lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.413</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.409.2::lts</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.403</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.426</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.412</vuln:product>
      <vuln:product>cpe:/a:cloudbees:jenkins:1.409.1:-:lts</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0158</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T17:55:01.253-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-26T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T15:17:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-01-04" xml:lang="en">https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-01-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/jenkinsci/jenkins/commit/c3d8e05a1b3d58b6c4dcff97394cb3a79608b4b2" xml:lang="en">https://github.com/jenkinsci/jenkins/commit/c3d8e05a1b3d58b6c4dcff97394cb3a79608b4b2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/jenkinsci/jenkins/commit/a9aff088f327278a8873aef47fa8f80d3c5932fd" xml:lang="en">https://github.com/jenkinsci/jenkins/commit/a9aff088f327278a8873aef47fa8f80d3c5932fd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/jenkinsci/jenkins/commit/94a8789b699132dd706021a6be1b78bc47f19602" xml:lang="en">https://github.com/jenkinsci/jenkins/commit/94a8789b699132dd706021a6be1b78bc47f19602</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/jenkinsci/jenkins/commit/4895eaafca468b7f0f1a3166b2fca7414f0d5da5" xml:lang="en">https://github.com/jenkinsci/jenkins/commit/4895eaafca468b7f0f1a3166b2fca7414f0d5da5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/jenkinsci/jenkins/commit/3dc13b957b14cec649036e8dd517f0f9cb21fb04" xml:lang="en">https://github.com/jenkinsci/jenkins/commit/3dc13b957b14cec649036e8dd517f0f9cb21fb04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=892795" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=892795</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/07/4" xml:lang="en">[oss-security] 20130107 Re: CVE Request: Jenkins possible remote code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-01-04.cb" xml:lang="en">http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-01-04.cb</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0220.html" xml:lang="en">RHSA-2013:0220</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in CloudBees Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0160">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.42</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.44</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.43</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0160</vuln:cve-id>
    <vuln:published-datetime>2013-02-17T23:41:50.277-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-04T23:40:33.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-18T11:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=892983" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=892983</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/08/3" xml:lang="en">[oss-security] 20130107 Re: /dev/ptmx timing</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.html" xml:lang="en">SUSE-SU-2013:0674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.html" xml:lang="en">openSUSE-SU-2013:0395</vuln:reference>
    </vuln:references>
    <vuln:summary>The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.0.a10"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.0.a9"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.0.a8"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.0.a7"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.0.a6"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.0.a5"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.0.a4"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.0.a3"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.0.a2"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:3.0.0.a1"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ryan_davis:ruby_parser:1.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:2.0.2</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.1</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:2.2.0</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.1.0</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:2.0.0</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.4</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:2.3.0</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:2.0.1</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.0.a6</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.1.1</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.0</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:2.0.5</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:2.0.4</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.0.a5</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.0.a10</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:2.1.0</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:1.0.0</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:2.3.1</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:2.0.3</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.3</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:2.0.6</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.0.a3</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.0.a7</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.2</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.0.a2</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.0.a8</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.0.a4</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.0.a9</vuln:product>
      <vuln:product>cpe:/a:ryan_davis:ruby_parser:3.0.0.a1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0162</vuln:cve-id>
    <vuln:published-datetime>2013-03-01T00:40:16.987-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-01T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-01T11:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=892806" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=892806</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0548.html" xml:lang="en">RHSA-2013:0548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0544.html" xml:lang="en">RHSA-2013:0544</vuln:reference>
    </vuln:references>
    <vuln:summary>The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0164">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:openshift_origin:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:openshift:1.0:-:enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:openshift:1.0:-:enterprise</vuln:product>
      <vuln:product>cpe:/a:redhat:openshift_origin:1.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0164</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T17:55:01.300-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T15:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/openshift/origin-server/pull/1136" xml:lang="en">https://github.com/openshift/origin-server/pull/1136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/openshift/origin-server/commit/524465f70a32d0eb6bf047e6a05c76c22d52bfa2" xml:lang="en">https://github.com/openshift/origin-server/commit/524465f70a32d0eb6bf047e6a05c76c22d52bfa2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=893307" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=893307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0220.html" xml:lang="en">RHSA-2013:0220</vuln:reference>
    </vuln:references>
    <vuln:summary>The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0166">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6f"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8t"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8m:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6k"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6j"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6m"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6l"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8n"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8o"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.2b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.1c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8l"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8w"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8p"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8m"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8k"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7m"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8j"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7f"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7j"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7k"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8u"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8f"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8r"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8q"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8s"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.7a-2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8v"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.6b-3"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.6-15"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7l"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8x"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0f"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0j"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.1b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.1c"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8m</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6:beta2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8s</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8q</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta3</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.6b-3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8t</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7k</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8r</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.2b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8f</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8o</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8k</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.1c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a:beta2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5a:beta2</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.7a-2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8w</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6:beta3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.1c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7f</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8v</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.1a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8x</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8l</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8m:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6l</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5a:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8n</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6f</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8j</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6j</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a:beta3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta5</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8u</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5:beta2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.3a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7g</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.6-15</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6k</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0f</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8p</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0g</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7l</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6m</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7j</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7m</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8g</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0j</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.1b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0166</vuln:cve-id>
    <vuln:published-datetime>2013-02-08T14:55:00.967-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-04T23:40:33.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-11T09:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=908052" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=908052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20130204.txt" xml:lang="en">http://www.openssl.org/news/secadv_20130204.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2621" xml:lang="en">DSA-2621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0783.html" xml:lang="en">RHSA-2013:0783</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0782.html" xml:lang="en">RHSA-2013:0782</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0587.html" xml:lang="en">RHSA-2013:0587</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=136396549913849&amp;w=2" xml:lang="en">HPSBUX02856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=136396549913849&amp;w=2" xml:lang="en">SSRT101104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=ebc71865f0506a293242bd4aec97cdc7a8ef24b0" xml:lang="en">http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=ebc71865f0506a293242bd4aec97cdc7a8ef24b0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=66e8211c0b1347970096e04b18aa52567c325200" xml:lang="en">http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=66e8211c0b1347970096e04b18aa52567c325200</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=62e4506a7d4cec1c8e1ff687f6b220f6a62a57c7" xml:lang="en">http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=62e4506a7d4cec1c8e1ff687f6b220f6a62a57c7</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0168">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:enterprise_virtualization_manager:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:enterprise_virtualization_manager:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:enterprise_virtualization_manager:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:enterprise_virtualization_manager:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:enterprise_virtualization_manager:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:enterprise_virtualization_manager:3.0</vuln:product>
      <vuln:product>cpe:/a:redhat:enterprise_virtualization_manager:2.1</vuln:product>
      <vuln:product>cpe:/a:redhat:enterprise_virtualization_manager:2.2.3</vuln:product>
      <vuln:product>cpe:/a:redhat:enterprise_virtualization_manager:2.2</vuln:product>
      <vuln:product>cpe:/a:redhat:enterprise_virtualization_manager:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0168</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T19:55:01.667-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-19T10:06:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=893355" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=893355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/81834" xml:lang="en">entreprise-movedisk-dos(81834)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id/1028076" xml:lang="en">1028076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57750" xml:lang="en">57750</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0211.html" xml:lang="en">RHSA-2013:0211</vuln:reference>
    </vuln:references>
    <vuln:summary>The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticated storage admins to cause a denial of service (free space consumption of other storage domains) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0169">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.1b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.1c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0f"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0j"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8f"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8j"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8k"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8l"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8m"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8n"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8o"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8p"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8q"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8r"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8s"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8t"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8u"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8v"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8w"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8x"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:openjdk:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:openjdk:1.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:openjdk:1.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:openjdk:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.14.0"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.13.1"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.99:pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.99:pre3"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.12.0"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:1.1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.99:pre4"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:0.99:pre5"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:polarssl:polarssl:1.1.0:rc0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8m</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:1.1.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8q</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8s</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:1.1.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8t</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:1.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:openjdk:1.8.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8r</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:1.1.3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.12.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8f</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8o</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.99:pre1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8k</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.1c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8w</vuln:product>
      <vuln:product>cpe:/a:oracle:openjdk:1.7.0</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.14.3</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.99:pre4</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.99:pre5</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8v</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.1a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.1</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.14.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0d</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.12.1</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.10.1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8x</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:1.1.4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8l</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.11.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8n</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.11.1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8j</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.13.1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8u</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8i</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:1.1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.14.2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0f</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8p</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.99:pre3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0g</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8b</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:1.1.0:rc0</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:1.1.1</vuln:product>
      <vuln:product>cpe:/a:polarssl:polarssl:0.10.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8g</vuln:product>
      <vuln:product>cpe:/a:oracle:openjdk:1.6.0</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0j</vuln:product>
      <vuln:product>cpe:/a:oracle:openjdk:-</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.1b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0169</vuln:cve-id>
    <vuln:published-datetime>2013-02-08T14:55:01.030-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-04T23:40:33.597-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-11T10:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA13-051A.html" xml:lang="en">TA13-051A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://polarssl.org/tech-updates/releases/polarssl-1.2.5-released" xml:lang="en">https://polarssl.org/tech-updates/releases/polarssl-1.2.5-released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1735-1" xml:lang="en">USN-1735-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20130204.txt" xml:lang="en">http://www.openssl.org/news/secadv_20130204.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.matrixssl.org/news.html" xml:lang="en">http://www.matrixssl.org/news.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.isg.rhul.ac.uk/tls/TLStiming.pdf" xml:lang="en">http://www.isg.rhul.ac.uk/tls/TLStiming.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2622" xml:lang="en">DSA-2622</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2621" xml:lang="en">DSA-2621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0783.html" xml:lang="en">RHSA-2013:0783</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0782.html" xml:lang="en">RHSA-2013:0782</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0587.html" xml:lang="en">RHSA-2013:0587</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2013/02/05/24" xml:lang="en">[oss-security] 20130205 Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" xml:lang="en">SSRT101184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" xml:lang="en">HPSBMU02874</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" xml:lang="en">HPSBUX02857</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" xml:lang="en">SSRT101103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=136396549913849&amp;w=2" xml:lang="en">HPSBUX02856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=136396549913849&amp;w=2" xml:lang="en">SSRT101104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00002.html" xml:lang="en">openSUSE-SU-2013:0378</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00000.html" xml:lang="en">openSUSE-SU-2013:0375</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00020.html" xml:lang="en">SUSE-SU-2013:0328</vuln:reference>
    </vuln:references>
    <vuln:summary>The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0170">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt:0.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt:0.10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt:0.10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt::0.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt::0.9.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt::0.9.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt::0.9.11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt::0.9.11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt::0.9.11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt::0.9.11.6"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt::0.9.11.7"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt::0.9.11.8"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt:0.9.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt:0.9.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:libvirt:0.9.6.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:libvirt:0.10.2.2</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt::0.9.11.4</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt:0.10.2.1</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt::0.9.11</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt::0.9.11.8</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt::0.9.11.3</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt:0.9.6.1</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt::0.9.11.7</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt:1.0.0</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt::0.9.11.2</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt:0.10.2</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt::0.9.11.1</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt:1.0.1</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt:0.9.6.2</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt:0.9.6</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt::0.9.11.5</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt:0.9.6.3</vuln:product>
      <vuln:product>cpe:/a:redhat:libvirt::0.9.11.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0170</vuln:cve-id>
    <vuln:published-datetime>2013-02-08T15:55:01.297-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-07T23:11:31.173-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-11T11:26:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=893450" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=893450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/81552" xml:lang="en">libvirt-virnetmessagefree-code-exec(81552)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1708-1" xml:lang="en">USN-1708-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id/1028047" xml:lang="en">1028047</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57578" xml:lang="en">57578</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.libvirt.org/page/Maintenance_Releases" xml:lang="en">http://wiki.libvirt.org/page/Maintenance_Releases</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52003" xml:lang="en">52003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52001" xml:lang="en">52001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0199.html" xml:lang="en">RHSA-2013:0199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/89644" xml:lang="en">89644</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00016.html" xml:lang="en">SUSE-SU-2013:0320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00002.html" xml:lang="en">openSUSE-SU-2013:0275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00001.html" xml:lang="en">openSUSE-SU-2013:0274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098398.html" xml:lang="en">FEDORA-2013-1626</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098370.html" xml:lang="en">FEDORA-2013-1642</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098326.html" xml:lang="en">FEDORA-2013-1644</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://libvirt.org/news.html" xml:lang="en">http://libvirt.org/news.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://libvirt.org/git/?p=libvirt.git;a=commit;h=46532e3e8ed5f5a736a02f67d6c805492f9ca720" xml:lang="en">http://libvirt.org/git/?p=libvirt.git;a=commit;h=46532e3e8ed5f5a736a02f67d6c805492f9ca720</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0172">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:4.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:4.0.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0172</vuln:cve-id>
    <vuln:published-datetime>2013-01-17T16:55:00.947-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-01-18T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-18T13:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.samba.org/samba/security/CVE-2013-0172" xml:lang="en">http://www.samba.org/samba/security/CVE-2013-0172</vuln:reference>
    </vuln:references>
    <vuln:summary>Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifying LDAP directory objects by leveraging (1) objectClass access by a user, (2) objectClass access by a group, or (3) write access to an attribute.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:erik_michaels-ober:multi_xml:0.5.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:grape_project:grape:0.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:grape_project:grape:0.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:grape_project:grape:0.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:grape_project:grape:0.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:grape_project:grape:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:grape_project:grape:0.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:grape_project:grape:0.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:grape_project:grape:0.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:grape_project:grape:0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:grape_project:grape:0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:grape_project:grape:0.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:grape_project:grape:0.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:erik_michaels-ober:multi_xml:0.5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:grape_project:grape:0.1.5</vuln:product>
      <vuln:product>cpe:/a:grape_project:grape:0.2.3</vuln:product>
      <vuln:product>cpe:/a:grape_project:grape:0.1.3</vuln:product>
      <vuln:product>cpe:/a:grape_project:grape:0.1.1</vuln:product>
      <vuln:product>cpe:/a:grape_project:grape:0.2.0</vuln:product>
      <vuln:product>cpe:/a:grape_project:grape:0.2.5</vuln:product>
      <vuln:product>cpe:/a:erik_michaels-ober:multi_xml:0.5.2</vuln:product>
      <vuln:product>cpe:/a:grape_project:grape:0.1.4</vuln:product>
      <vuln:product>cpe:/a:grape_project:grape:0.2.2</vuln:product>
      <vuln:product>cpe:/a:grape_project:grape:0.2.4</vuln:product>
      <vuln:product>cpe:/a:grape_project:grape:0.1.2</vuln:product>
      <vuln:product>cpe:/a:grape_project:grape:0.1.0</vuln:product>
      <vuln:product>cpe:/a:grape_project:grape:0.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0175</vuln:cve-id>
    <vuln:published-datetime>2013-04-25T19:55:01.410-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-26T23:15:09.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-26T10:25:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://news.ycombinator.com/item?id=5040457" xml:lang="en">https://news.ycombinator.com/item?id=5040457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://groups.google.com/forum/?fromgroups=#%21topic/ruby-grape/fthDkMgIOa0" xml:lang="en">https://groups.google.com/forum/?fromgroups=#!topic/ruby-grape/fthDkMgIOa0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/sferik/multi_xml/pull/34" xml:lang="en">https://github.com/sferik/multi_xml/pull/34</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://gist.github.com/nate/d7f6d9f4925f413621aa" xml:lang="en">https://gist.github.com/nate/d7f6d9f4925f413621aa</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/11/9" xml:lang="en">[oss-security] 20130111 Re: CVE request for multi_xml ruby gem (has same problem as CVE-2013-0156)</vuln:reference>
    </vuln:references>
    <vuln:summary>multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:libssh:libssh:0.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:libssh:libssh:0.5.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:libssh:libssh:0.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:libssh:libssh:0.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:libssh:libssh:0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:libssh:libssh:0.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:libssh:libssh:0.5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:libssh:libssh:0.4.7</vuln:product>
      <vuln:product>cpe:/a:libssh:libssh:0.4.8</vuln:product>
      <vuln:product>cpe:/a:libssh:libssh:0.5.1</vuln:product>
      <vuln:product>cpe:/a:libssh:libssh:0.5.0</vuln:product>
      <vuln:product>cpe:/a:libssh:libssh:0.5.3</vuln:product>
      <vuln:product>cpe:/a:libssh:libssh:0.5.0:rc1</vuln:product>
      <vuln:product>cpe:/a:libssh:libssh:0.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0176</vuln:cve-id>
    <vuln:published-datetime>2013-02-05T18:55:01.850-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-06T13:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.libssh.org/2013/01/22/libssh-0-5-4-security-release/" xml:lang="en">http://www.libssh.org/2013/01/22/libssh-0-5-4-security-release/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/81595" xml:lang="en">libssh-publickeyfromprivatekey-dos(81595)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1707-1" xml:lang="en">USN-1707-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51982" xml:lang="en">51982</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098094.html" xml:lang="en">FEDORA-2013-1407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098065.html" xml:lang="en">FEDORA-2013-1422</vuln:reference>
    </vuln:references>
    <vuln:summary>The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0181">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.0:rc1"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.0:beta10"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.0:beta9"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.0:beta8"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.0:beta7"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.0:beta6"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.0:beta5"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.0:beta4"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.0:beta3"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.0:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.0:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:thomas_seidl:search_api:7.x-1.x:dev"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.0:beta4</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.0:beta10</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.0:beta9</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.0:beta2</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.3</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.0:beta3</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.0:beta7</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.0</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.1</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.0:beta5</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.0:beta6</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.x:dev</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.2</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:thomas_seidl:search_api:7.x-1.0:beta8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0181</vuln:cve-id>
    <vuln:published-datetime>2013-03-27T17:55:01.477-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-28T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-28T09:55:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://drupal.org/node/1884332" xml:lang="en">https://drupal.org/node/1884332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://drupal.org/node/1884076" xml:lang="en">https://drupal.org/node/1884076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/15/3" xml:lang="en">[oss-security] 20130114 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupalcode.org/project/search_api.git/commitdiff/35b5728" xml:lang="en">http://drupalcode.org/project/search_api.git/commitdiff/35b5728</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Views in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using certain backends and facets, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0182">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.0:beta3"/>
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.0:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.0:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.0:alpha6"/>
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.0:alpha5"/>
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.0:alpha4"/>
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.0:alpha3"/>
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.0:alpha2"/>
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.0:alpha1"/>
          <cpe-lang:fact-ref name="cpe:/a:bart_feenstra:payment::7.x-1.x:dev"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.0:alpha2</vuln:product>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.0:alpha4</vuln:product>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.0:beta2</vuln:product>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.0:alpha1</vuln:product>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.0:alpha3</vuln:product>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.x:dev</vuln:product>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.0:alpha6</vuln:product>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.0:alpha5</vuln:product>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.0:beta3</vuln:product>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.1</vuln:product>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.2</vuln:product>
      <vuln:product>cpe:/a:bart_feenstra:payment::7.x-1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0182</vuln:cve-id>
    <vuln:published-datetime>2013-03-27T17:55:02.107-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-28T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-28T10:05:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://drupal.org/node/1884360" xml:lang="en">https://drupal.org/node/1884360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/1883830" xml:lang="en">http://drupal.org/node/1883830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/15/3" xml:lang="en">[oss-security] 20130114 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupalcode.org/project/payment.git/commitdiff/62c9186" xml:lang="en">http://drupalcode.org/project/payment.git/commitdiff/62c9186</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://drupal.org/node/1871508" xml:lang="en">http://drupal.org/node/1871508</vuln:reference>
    </vuln:references>
    <vuln:summary>The Payment module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to payments, which allows remote attackers to read arbitrary payments.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0183">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rack_project:rack:1.3.4</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.6</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.2</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.1</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.1</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.5</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.7</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.0</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.2</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.3</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0183</vuln:cve-id>
    <vuln:published-datetime>2013-03-01T00:40:17.037-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-14T23:33:53.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-01T11:49:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://groups.google.com/forum/#%21topic/rack-devel/7ZKPNAjgRSs" xml:lang="en">https://groups.google.com/forum/#!topic/rack-devel/7ZKPNAjgRSs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://groups.google.com/forum/#%21topic/rack-devel/-MWPHDeGWtI" xml:lang="en">https://groups.google.com/forum/#!topic/rack-devel/-MWPHDeGWtI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/rack/rack/commit/f95113402b7239f225282806673e1b6424522b18" xml:lang="en">https://github.com/rack/rack/commit/f95113402b7239f225282806673e1b6424522b18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/rack/rack/commit/548b9af2dc0059f4c0c19728624448d84de450ff" xml:lang="en">https://github.com/rack/rack/commit/548b9af2dc0059f4c0c19728624448d84de450ff</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=895282" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=895282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0548.html" xml:lang="en">RHSA-2013:0548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0544.html" xml:lang="en">RHSA-2013:0544</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://rack.github.com/" xml:lang="en">http://rack.github.com/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html" xml:lang="en">openSUSE-SU-2013:0462</vuln:reference>
    </vuln:references>
    <vuln:summary>multipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a long string in a Multipart HTTP packet.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0184">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rack_project:rack:1.3.4</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.6</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.3</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.1.0</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.1</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.1.2</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.1.4</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.5</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.6</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.8</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.2</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.2</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.4</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.3</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.0</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.1</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.2</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.1</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.7</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.0</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.1.3</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.3</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0184</vuln:cve-id>
    <vuln:published-datetime>2013-03-01T00:40:17.097-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-14T23:33:53.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-01T11:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=895384" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=895384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0548.html" xml:lang="en">RHSA-2013:0548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0544.html" xml:lang="en">RHSA-2013:0544</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html" xml:lang="en">openSUSE-SU-2013:0462</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Rack::Auth::AbstractRequest in Rack 1.1.x before 1.1.5, 1.2.x before 1.2.7, 1.3.x before 1.3.9, and 1.4.x before 1.4.4 allows remote attackers to cause a denial of service via unknown vectors related to "symbolized arbitrary strings."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0189">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.1.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid-cache:squid:3.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.04:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:11.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:10.04:-:lts"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.13</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.13</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.11</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.4</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.10</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.2</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.6</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.3</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.16</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.4</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.14</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:11.10</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.17</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.17</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.18</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.9</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.04:-:lts</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.6</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.9</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:10.04:-:lts</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.7</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.5.1</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.15</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.5</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.12</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.7</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.1</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.10</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.2</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.3</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.7</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.12</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.8</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.8</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.3</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.4</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.3</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.5</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.9</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.10</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.2</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.1</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.15</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.5</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.8</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.2</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.15</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.22</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.11</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.18</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.16</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.14</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.13</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.1</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.11</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.10</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.6</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.19</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.0.12</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.1</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.1.4</vuln:product>
      <vuln:product>cpe:/a:squid-cache:squid:3.2.0.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0189</vuln:cve-id>
    <vuln:published-datetime>2013-02-08T15:55:01.377-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-07T23:11:31.483-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-11T12:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v3/3.2/changesets/SQUID-2012_1.patch" xml:lang="en">http://www.squid-cache.org/Versions/v3/3.2/changesets/SQUID-2012_1.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v3/3.1/changesets/SQUID-2012_1.patch" xml:lang="en">http://www.squid-cache.org/Versions/v3/3.1/changesets/SQUID-2012_1.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/scm-commits/2013-January/934637.html" xml:lang="en">[scm-commits] 20130125 [squid/f17] CVE-2013-0189: Incomplete fix for the CVE-2012-5643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=895972" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=895972</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=887962#c9" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=887962#c9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1713-1" xml:lang="en">USN-1713-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57646" xml:lang="en">57646</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2631" xml:lang="en">DSA-2631</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52024" xml:lang="en">52024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bazaar.launchpad.net/~squid/squid/3.2/revision/11744" xml:lang="en">http://bazaar.launchpad.net/~squid/squid/3.2/revision/11744</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bazaar.launchpad.net/~squid/squid/3.2/revision/11743" xml:lang="en">http://bazaar.launchpad.net/~squid/squid/3.2/revision/11743</vuln:reference>
    </vuln:references>
    <vuln:summary>cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a denial of service (resource consumption) via a crafted request.  NOTE: this issue is due to an incorrect fix for CVE-2012-5643, possibly involving an incorrect order of arguments or incorrect comparison.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0190">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.23</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0190</vuln:cve-id>
    <vuln:published-datetime>2013-02-12T20:55:03.307-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-07T23:11:31.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:07:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=896038" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=896038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1728-1" xml:lang="en">USN-1728-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1725-1" xml:lang="en">USN-1725-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57433" xml:lang="en">57433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/16/8" xml:lang="en">[oss-security] 20130116 Xen Security Advisory 40 (CVE-2013-0190) - Linux stack corruption in xen_failsafe_callback for 32bit PVOPS guests.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/16/6" xml:lang="en">[oss-security] 20130116 [PATCH] xen: Fix stack corruption in xen_failsafe_callback for 32bit PVOPS guests.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0496.html" xml:lang="en">RHSA-2013:0496</vuln:reference>
    </vuln:references>
    <vuln:summary>The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a denial of service (guest crash) by triggering an iret fault, leading to use of an incorrect stack pointer and stack corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0198">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:0.95"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:0.98"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:0.96"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:0.996"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:0.992"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.25"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.13"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.45"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.46"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.47"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.48"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.41"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.42"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.43"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.44"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.49"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.22"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.40"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.35"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.36"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.37"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.38"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.39"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.31"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.30"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.34"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.33"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.27"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.26"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.29"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.28"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.21"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.20"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.24"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.23"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.17"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.16"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.19"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.18"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.50"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.51"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.52"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.53"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.54"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.55"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.56"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.57"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.58"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.59"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.60"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.61"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:-"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.62"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.63"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.64"/>
        <cpe-lang:fact-ref name="cpe:/a:thekelleys:dnsmasq:2.65"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.23</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.8</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.17</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.16</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:0.96</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.16</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.13</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.41</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.7</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.35</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.49</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.61</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.2</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.0</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.62</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.11</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.58</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.4</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.42</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.50</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.9</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.3</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.22</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.46</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.24</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.14</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.5</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.64</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.54</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.28</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.6</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:0.992</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.60</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.12</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.0</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.10</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.18</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.12</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.33</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.59</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.48</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.25</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.26</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.36</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.27</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:0.996</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.55</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.47</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:0.6</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:-</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.53</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.6</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.65</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.14</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.45</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.20</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.21</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.9</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.30</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.52</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.56</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.57</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.18</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.29</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.15</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.51</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.34</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.17</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.44</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.15</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.39</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.19</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.13</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:0.95</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.38</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:0.4</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.40</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:0.98</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.4</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.37</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.3</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.63</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.7</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:0.5</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.31</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.43</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.2</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:0.7</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.10</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:2.1</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.11</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.8</vuln:product>
      <vuln:product>cpe:/a:thekelleys:dnsmasq:1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0198</vuln:cve-id>
    <vuln:published-datetime>2013-03-05T16:38:54.827-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-06T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-06T08:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=22ce550e5346947a12a781ed0959a7b1165d0dc6" xml:lang="en">http://www.thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=22ce550e5346947a12a781ed0959a7b1165d0dc6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=894486" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=894486</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/18/7" xml:lang="en">[oss-security] 20130118 Re: CVE Request -- dnsmasq: Incomplete fix for the CVE-2012-3411 issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/18/2" xml:lang="en">[oss-security] 20130118 CVE Request -- dnsmasq: Incomplete fix for the CVE-2012-3411 issue</vuln:reference>
    </vuln:references>
    <vuln:summary>Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0200">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.12.4"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.11.10"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.11.7"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.11.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.10.9"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.9.12"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.9.4b"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:3.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:2.7.10"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:linux_imaging_and_printing_project:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.9.10</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.11.7</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:1.0</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.9.4</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.9.12</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.10.2</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.11.3a</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:2.7.10</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.12.4</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.11.3</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.10.5</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.11.5</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.11.1</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.9.8</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.10.9</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:2.0</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.11.10</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.10.6</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:6</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.9.2</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.9.4b</vuln:product>
      <vuln:product>cpe:/a:hp:linux_imaging_and_printing_project:3.9.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0200</vuln:cve-id>
    <vuln:published-datetime>2013-03-06T15:55:01.293-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-07T09:42:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-59"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.scientificlinux.org/linux/scientific/6x/SRPMS/vendor/hplip-3.12.4-4.el6.src.rpm" xml:lang="en">ftp://ftp.scientificlinux.org/linux/scientific/6x/SRPMS/vendor/hplip-3.12.4-4.el6.src.rpm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=902163" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=902163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://hplipopensource.com/hplip-web/release_notes.html" xml:lang="en">http://hplipopensource.com/hplip-web/release_notes.html</vuln:reference>
    </vuln:references>
    <vuln:summary>HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0205">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:restful_web_services_project:restws:7.x-2.x:dev"/>
          <cpe-lang:fact-ref name="cpe:/a:restful_web_services_project:restws:7.x-2.0:alpha2"/>
          <cpe-lang:fact-ref name="cpe:/a:restful_web_services_project:restws:7.x-2.0:alpha1"/>
          <cpe-lang:fact-ref name="cpe:/a:restful_web_services_project:restws:7.x-1.x:dev"/>
          <cpe-lang:fact-ref name="cpe:/a:restful_web_services_project:restws:7.x-1.0:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:restful_web_services_project:restws:7.x-1.0:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:restful_web_services_project:restws:7.x-1.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:restful_web_services_project:restws:7.x-1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:restful_web_services_project:restws:7.x-2.0:alpha1</vuln:product>
      <vuln:product>cpe:/a:restful_web_services_project:restws:7.x-1.0:beta2</vuln:product>
      <vuln:product>cpe:/a:restful_web_services_project:restws:7.x-1.x:dev</vuln:product>
      <vuln:product>cpe:/a:restful_web_services_project:restws:7.x-1.0</vuln:product>
      <vuln:product>cpe:/a:restful_web_services_project:restws:7.x-2.x:dev</vuln:product>
      <vuln:product>cpe:/a:restful_web_services_project:restws:7.x-2.0:alpha2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0205</vuln:cve-id>
    <vuln:published-datetime>2013-03-19T10:55:01.090-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T04:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://drupal.org/node/1890216" xml:lang="en">https://drupal.org/node/1890216</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://drupal.org/node/1890212" xml:lang="en">https://drupal.org/node/1890212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://drupal.org/node/1890222" xml:lang="en">https://drupal.org/node/1890222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/21/5" xml:lang="en">[oss-security] 20130121 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0206">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:guy_bedford:live_css:6.x-2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:guy_bedford:live_css:7.x-2.6"/>
          <cpe-lang:fact-ref name="cpe:/a:guy_bedford:live_css:7.x-2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:guy_bedford:live_css:7.x-2.4"/>
          <cpe-lang:fact-ref name="cpe:/a:guy_bedford:live_css:7.x-2.3"/>
          <cpe-lang:fact-ref name="cpe:/a:guy_bedford:live_css:7.x-2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:guy_bedford:live_css:7.x-2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:guy_bedford:live_css:7.x-2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:guy_bedford:live_css:7.x-2.0-beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:guy_bedford:live_css:7.x-2.x-dev"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:guy_bedford:live_css:7.x-2.5</vuln:product>
      <vuln:product>cpe:/a:guy_bedford:live_css:7.x-2.6</vuln:product>
      <vuln:product>cpe:/a:guy_bedford:live_css:7.x-2.2</vuln:product>
      <vuln:product>cpe:/a:guy_bedford:live_css:7.x-2.0-beta1</vuln:product>
      <vuln:product>cpe:/a:guy_bedford:live_css:7.x-2.0</vuln:product>
      <vuln:product>cpe:/a:guy_bedford:live_css:6.x-2.0</vuln:product>
      <vuln:product>cpe:/a:guy_bedford:live_css:7.x-2.3</vuln:product>
      <vuln:product>cpe:/a:guy_bedford:live_css:7.x-2.x-dev</vuln:product>
      <vuln:product>cpe:/a:guy_bedford:live_css:7.x-2.4</vuln:product>
      <vuln:product>cpe:/a:guy_bedford:live_css:7.x-2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0206</vuln:cve-id>
    <vuln:published-datetime>2013-03-19T10:55:02.620-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-21T05:26:43.427-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T05:10:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://drupal.org/node/1890318" xml:lang="en">https://drupal.org/node/1890318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/21/5" xml:lang="en">[oss-security] 20130121 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupalcode.org/project/live_css.git/commitdiff/ef323c8" xml:lang="en">http://drupalcode.org/project/live_css.git/commitdiff/ef323c8</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupalcode.org/project/live_css.git/commitdiff/cb7005f" xml:lang="en">http://drupalcode.org/project/live_css.git/commitdiff/cb7005f</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/1883978" xml:lang="en">http://drupal.org/node/1883978</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/1883976" xml:lang="en">http://drupal.org/node/1883976</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "administer CSS" permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0207">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:leighton_whiting:mark_complete"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:leighton_whiting:mark_complete</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0207</vuln:cve-id>
    <vuln:published-datetime>2013-03-19T10:55:02.637-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-21T10:21:46.953-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T10:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://drupal.org/node/1890566" xml:lang="en">https://drupal.org/node/1890566</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://drupal.org/node/1890538" xml:lang="en">https://drupal.org/node/1890538</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/21/5" xml:lang="en">[oss-security] 20130121 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupalcode.org/project/mark_complete.git/commitdiff/a18c7b2" xml:lang="en">http://drupalcode.org/project/mark_complete.git/commitdiff/a18c7b2</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in the Mark Complete module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0208">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openstack:essex:-"/>
        <cpe-lang:fact-ref name="cpe:/a:openstack:folsom:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.04:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:11.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:11.10</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.04:-:lts</vuln:product>
      <vuln:product>cpe:/a:openstack:folsom:-</vuln:product>
      <vuln:product>cpe:/a:openstack:essex:-</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0208</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T11:55:01.617-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-14T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-14T08:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/openstack/nova/commit/317cc0af385536dee43ef2addad50a91357fc1ad" xml:lang="en">https://github.com/openstack/nova/commit/317cc0af385536dee43ef2addad50a91357fc1ad</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/openstack/nova/commit/243d516cea9d3caa5a8267b12d2f577dcb24193b" xml:lang="en">https://github.com/openstack/nova/commit/243d516cea9d3caa5a8267b12d2f577dcb24193b</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=902629" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=902629</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.launchpad.net/nova/+bug/1069904" xml:lang="en">https://bugs.launchpad.net/nova/+bug/1069904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/81697" xml:lang="en">nova-volume-security-bypass(81697)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1709-1" xml:lang="en">USN-1709-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57613" xml:lang="en">57613</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/29/9" xml:lang="en">[oss-security] 20130129 [OSSA 2013-001] Boot from volume allows access to random volumes (CVE-2013-0208)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51992" xml:lang="en">51992</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51963" xml:lang="en">51963</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0208.html" xml:lang="en">RHSA-2013:0208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/89661" xml:lang="en">89661</vuln:reference>
    </vuln:references>
    <vuln:summary>The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the block_device_mapping parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0209">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.21"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.22"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.23"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.24"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.25"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.26"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.261"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.27"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.28"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.29"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.291"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.292"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.31"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.32"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.33"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.34"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.35"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.36"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.361"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.37"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.38"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.28::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.28::open_source"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.29::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.29::open_source"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.291::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.291::open_source"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.292::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.292::open_source"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.36::open_source"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.361::open_source"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.37::open_source"/>
        <cpe-lang:fact-ref name="cpe:/a:sixapart:movable_type:4.38::open_source"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sixapart:movable_type:4.361::open_source</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.27</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.29</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.26</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.28</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.38</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.32</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.29::open_source</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.33</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.37</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.38::open_source</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.36::open_source</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.22</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.292</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.291</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.31</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.23</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.361</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.28::open_source</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.292::enterprise</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.36</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.261</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.37::open_source</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.292::open_source</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.35</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.21</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.28::enterprise</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.291::open_source</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.34</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.291::enterprise</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.25</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.24</vuln:product>
      <vuln:product>cpe:/a:sixapart:movable_type:4.29::enterprise</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0209</vuln:cve-id>
    <vuln:published-datetime>2013-01-22T20:55:01.150-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-01-29T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-23T10:47:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.movabletype.org/2013/01/movable_type_438_patch.html" xml:lang="en">http://www.movabletype.org/2013/01/movable_type_438_patch.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.sec-1.com/blog/wp-content/uploads/2013/01/movabletype_upgrade_exec.rb_.txt" xml:lang="en">http://www.sec-1.com/blog/wp-content/uploads/2013/01/movabletype_upgrade_exec.rb_.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.sec-1.com/blog/?p=402" xml:lang="en">http://www.sec-1.com/blog/?p=402</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2013/01/22/3" xml:lang="en">[oss-security] 20130121 Re: CVE request for Movable Type</vuln:reference>
    </vuln:references>
    <vuln:summary>lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0212">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openstack:essex:2012.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openstack:folsom:2012.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openstack:glance:grizzly"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.04:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:11.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:11.10</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.04:-:lts</vuln:product>
      <vuln:product>cpe:/a:openstack:glance:grizzly</vuln:product>
      <vuln:product>cpe:/a:openstack:essex:2012.1</vuln:product>
      <vuln:product>cpe:/a:openstack:folsom:2012.2</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0212</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T16:55:01.143-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-26T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T14:55:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=902964" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=902964</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-1710-1" xml:lang="en">USN-1710-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.launchpad.net/openstack/msg20517.html" xml:lang="en">[openstack] 20130129 [OSSA 2013-002] Backend password leak in Glance error message (CVE-2013-0212)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://launchpad.net/glance/+milestone/2012.2.3" xml:lang="en">https://launchpad.net/glance/+milestone/2012.2.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/openstack/glance/commit/e96273112b5b5da58d970796b7cfce04c5030a89" xml:lang="en">https://github.com/openstack/glance/commit/e96273112b5b5da58d970796b7cfce04c5030a89</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/openstack/glance/commit/96a470be64adcef97f235ca96ed3c59ed954a4c1" xml:lang="en">https://github.com/openstack/glance/commit/96a470be64adcef97f235ca96ed3c59ed954a4c1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/openstack/glance/commit/37d4d96bf88c2bf3e7e9511b5e321cf4bed364b7" xml:lang="en">https://github.com/openstack/glance/commit/37d4d96bf88c2bf3e7e9511b5e321cf4bed364b7</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.launchpad.net/glance/+bug/1098962" xml:lang="en">https://bugs.launchpad.net/glance/+bug/1098962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/29/10" xml:lang="en">[oss-security] 20130129 [OSSA 2013-002] Backend password leak in Glance error message (CVE-2013-0212)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51990" xml:lang="en">51990</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51957" xml:lang="en">51957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0209.html" xml:lang="en">RHSA-2013:0209</vuln:reference>
    </vuln:references>
    <vuln:summary>store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0213">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.20"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.19"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.18"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.17"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.16"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.15"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.14"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.13"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.13"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.14a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23d"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.2a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23:d"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23:c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.34"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23:b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21:c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21:b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.31"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.26a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.30"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20:b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.33"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.2:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.28:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.27:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.26:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.14:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20:a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:4.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:3.4.14</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.13</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.15</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.26a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:rc2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23d</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:rc3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.26:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.14a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:pre1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.13</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.13</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.15</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.33</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.4:rc1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.13</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:rc1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.18</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21:c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20:b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.12</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.2:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.19</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.19</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.28</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.14</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.16</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.16</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.14:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.16</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23:d</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.28:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.12</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.13</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.31</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.15</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.15</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23:c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.15</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.27</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.12</vuln:product>
      <vuln:product>cpe:/a:samba:samba:4.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.29</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.2a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.22</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:pre2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:4.0.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.17</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.36</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.16</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.27:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.24</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.12</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.32</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.34</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.18</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21:b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.14</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.17</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.20</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.14</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.30</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.14</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.26</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.35</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.17</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23:b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.37</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0213</vuln:cve-id>
    <vuln:published-datetime>2013-02-02T15:55:03.100-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-14T23:33:55.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-04T12:45:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.samba.org/samba/security/CVE-2013-0213" xml:lang="en">http://www.samba.org/samba/security/CVE-2013-0213</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2617" xml:lang="en">DSA-2617</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-02/msg00033.html" xml:lang="en">openSUSE-SU-2013:0281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-02/msg00029.html" xml:lang="en">openSUSE-SU-2013:0277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00042.html" xml:lang="en">SUSE-SU-2013:0519</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00019.html" xml:lang="en">SUSE-SU-2013:0326</vuln:reference>
    </vuln:references>
    <vuln:summary>The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0214">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.20"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.19"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.18"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.17"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.16"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.15"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.14"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.13"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.13"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.14a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23d"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.2a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23:d"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23:c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.34"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23:b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21:c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21:b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.31"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.26a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.30"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20:b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.33"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.2:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.28:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.27:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.26:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.25:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.14:a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20:a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.6.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:4.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:3.4.14</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.13</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.15</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.26a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:rc2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23d</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:rc3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.26:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.14a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:pre1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.13</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.13</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.15</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.33</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.4:rc1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.13</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:rc1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.18</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21:c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20:b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.12</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.2:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.19</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.19</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.28</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.14</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.16</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.16</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.14:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.16</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23:d</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.28:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.12</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.13</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.31</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.15</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.15</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23:c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.15</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.27</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.12</vuln:product>
      <vuln:product>cpe:/a:samba:samba:4.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.29</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.2a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.6.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.22</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:pre2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.2</vuln:product>
      <vuln:product>cpe:/a:samba:samba:4.0.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.17</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.36</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.16</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.27:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.24</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.12</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.5</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.32</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.34</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.18</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.0</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21:b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.14</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.17</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.20</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.14</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.30</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.1</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.14</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.26</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.3.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20:a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.3</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.4.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.35</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.17</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25:b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23:b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.25c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.37</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.5.4</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.2.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0214</vuln:cve-id>
    <vuln:published-datetime>2013-02-02T15:55:03.147-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-14T23:33:55.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-04T12:48:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.samba.org/samba/security/CVE-2013-0214" xml:lang="en">http://www.samba.org/samba/security/CVE-2013-0214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2617" xml:lang="en">DSA-2617</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-02/msg00033.html" xml:lang="en">openSUSE-SU-2013:0281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-02/msg00029.html" xml:lang="en">openSUSE-SU-2013:0277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00042.html" xml:lang="en">SUSE-SU-2013:0519</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00019.html" xml:lang="en">SUSE-SU-2013:0326</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0215">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:xen:xen:4.2.0</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.2.1</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.4</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.3</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.2</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.1</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0215</vuln:cve-id>
    <vuln:published-datetime>2013-03-07T00:04:44.667-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-07T23:11:32.090-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-07T10:38:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=61401264eb00fae4ee4efc8e9a5067449283207b" xml:lang="en">http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=61401264eb00fae4ee4efc8e9a5067449283207b</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=40f9c5e0a6d15b4ca1f6d4ed3a46f0871520eab5" xml:lang="en">http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=40f9c5e0a6d15b4ca1f6d4ed3a46f0871520eab5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://openwall.com/lists/oss-security/2013/02/05/10" xml:lang="en">[oss-security] 20130205 Xen Security Advisory 38 (CVE-2013-0215) - oxenstored incorrect handling of certain Xenbus ring states</vuln:reference>
    </vuln:references>
    <vuln:summary>oxenstored in Xen 4.1.x, Xen 4.2.x, and xen-unstable does not properly consider the state of the Xenstore ring during read operations, which allows guest OS users to cause a denial of service (daemon crash and host-control outage, or memory consumption) or obtain sensitive control-plane data by leveraging guest administrative access.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0216">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.42</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.44</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.43</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0216</vuln:cve-id>
    <vuln:published-datetime>2013-02-17T23:41:50.323-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-04T23:40:35.730-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.2</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-18T11:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/torvalds/linux/commit/48856286b64e4b66ec62b94e504d0b29c1ade664" xml:lang="en">https://github.com/torvalds/linux/commit/48856286b64e4b66ec62b94e504d0b29c1ade664</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=48856286b64e4b66ec62b94e504d0b29c1ade664" xml:lang="en">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=48856286b64e4b66ec62b94e504d0b29c1ade664</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=910883" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=910883</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/05/12" xml:lang="en">[oss-security] 20130205 Xen Security Advisory 39 (CVE-2013-0216,CVE-2013-0217) - Linux netback DoS via malicious guest ring.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.8" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.8</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.html" xml:lang="en">SUSE-SU-2013:0674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.html" xml:lang="en">openSUSE-SU-2013:0395</vuln:reference>
    </vuln:references>
    <vuln:summary>The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0217">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.42</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.44</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.43</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0217</vuln:cve-id>
    <vuln:published-datetime>2013-02-17T23:41:50.367-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-18T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.2</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-18T11:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/torvalds/linux/commit/7d5145d8eb2b9791533ffe4dc003b129b9696c48" xml:lang="en">https://github.com/torvalds/linux/commit/7d5145d8eb2b9791533ffe4dc003b129b9696c48</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=7d5145d8eb2b9791533ffe4dc003b129b9696c48" xml:lang="en">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=7d5145d8eb2b9791533ffe4dc003b129b9696c48</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=910883" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=910883</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/05/12" xml:lang="en">[oss-security] 20130205 Xen Security Advisory 39 (CVE-2013-0216,CVE-2013-0217) - Linux netback DoS via malicious guest ring.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.8" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.8</vuln:reference>
    </vuln:references>
    <vuln:summary>Memory leak in drivers/net/xen-netback/netback.c in the Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (memory consumption) by triggering certain error conditions.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0218">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_application_platform:5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_application_platform:5.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_web_platform:5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:jboss_enterprise_web_platform:5.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_application_platform:5.2.0</vuln:product>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_web_platform:5.2.0</vuln:product>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_web_platform:5.1.2</vuln:product>
      <vuln:product>cpe:/a:redhat:jboss_enterprise_application_platform:5.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0218</vuln:cve-id>
    <vuln:published-datetime>2013-02-05T18:55:01.897-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-06T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-06T12:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=903073" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=903073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/81725" xml:lang="en">jboss-eap-info-disc(81725)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57652" xml:lang="en">57652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/89698" xml:lang="en">89698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52041" xml:lang="en">52041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0207.html" xml:lang="en">RHSA-2013:0207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0206.html" xml:lang="en">RHSA-2013:0206</vuln:reference>
    </vuln:references>
    <vuln:summary>The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0219">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.2.91"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.1.91"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.1.92"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.99"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.99.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.99.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:5"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.6.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.6</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.3.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.3.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.2.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.0:beta3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.5</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.4.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.4.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.1.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.6.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.2.91</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.7.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.4</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.7</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.6</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.99.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.15</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.3.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.9.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.11</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.7.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.1.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.6.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.0:beta2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:5</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.6</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.6.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.1.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.2.4</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.3.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.9.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.9</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.8</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.2.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.2.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.12</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.10</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.99.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.14</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.2</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:6</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.5</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.0:beta1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.4.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.13</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.6.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.17</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.6.4</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.9.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.4.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.9.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.6.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.3.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.5</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.2.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.99</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.1.92</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.4</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.16</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.4</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.1.91</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.7.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.5.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.2.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.6.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0219</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T14:55:01.237-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-25T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T14:18:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4" xml:lang="en">https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://fedorahosted.org/sssd/ticket/1782" xml:lang="en">https://fedorahosted.org/sssd/ticket/1782</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=884254" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=884254</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57539" xml:lang="en">57539</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52315" xml:lang="en">52315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51928" xml:lang="en">51928</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0508.html" xml:lang="en">RHSA-2013:0508</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098613.html" xml:lang="en">FEDORA-2013-1826</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098434.html" xml:lang="en">FEDORA-2013-1795</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.fedorahosted.org/cgit/sssd.git/commit/?id=e864d914a44a37016736554e9257c06b18c57d37" xml:lang="en">http://git.fedorahosted.org/cgit/sssd.git/commit/?id=e864d914a44a37016736554e9257c06b18c57d37</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.fedorahosted.org/cgit/sssd.git/commit/?id=94cbf1cfb0f88c967f1fb0a4cf23723148868e4a" xml:lang="en">http://git.fedorahosted.org/cgit/sssd.git/commit/?id=94cbf1cfb0f88c967f1fb0a4cf23723148868e4a</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.fedorahosted.org/cgit/sssd.git/commit/?id=3843b284cd3e8f88327772ebebc7249990fd87b9" xml:lang="en">http://git.fedorahosted.org/cgit/sssd.git/commit/?id=3843b284cd3e8f88327772ebebc7249990fd87b9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.fedorahosted.org/cgit/sssd.git/commit/?id=020bf88fd1c5bdac8fc671b37c7118f5378c7047" xml:lang="en">http://git.fedorahosted.org/cgit/sssd.git/commit/?id=020bf88fd1c5bdac8fc671b37c7118f5378c7047</vuln:reference>
    </vuln:references>
    <vuln:summary>System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0220">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.8.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.2.91"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.1.91"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.1.92"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.99"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.99.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.99.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:fedoraproject:sssd:0.6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.6.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.6</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.3.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.3.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.2.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.0:beta3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.5</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.4.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.4.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.1.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.6.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.2.91</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.7.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.4</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.7</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.6</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.99.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.15</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.3.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.9.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.11</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.7.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.1.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.6.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.0:beta2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.6</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.6.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.1.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.2.4</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.3.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.9.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.9</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.8</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.2.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.2.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.12</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.10</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.99.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.14</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.5</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.0:beta1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.4.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.13</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.6.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.17</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.6.4</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.9.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.8.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.4.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.9.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.6.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.3.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.5</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.2.2</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.99</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.1.92</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.4</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.16</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.4</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.1.91</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.7.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.5.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.5.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.2.1</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.0.3</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:1.6.0</vuln:product>
      <vuln:product>cpe:/a:fedoraproject:sssd:0.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0220</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T14:55:01.300-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-27T14:50:57.027-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T14:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4" xml:lang="en">https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://fedorahosted.org/sssd/ticket/1781" xml:lang="en">https://fedorahosted.org/sssd/ticket/1781</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=884601" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=884601</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57539" xml:lang="en">57539</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52315" xml:lang="en">52315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51928" xml:lang="en">51928</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0508.html" xml:lang="en">RHSA-2013:0508</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098613.html" xml:lang="en">FEDORA-2013-1826</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098434.html" xml:lang="en">FEDORA-2013-1795</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.fedorahosted.org/cgit/sssd.git/commit/?id=30e2585dd46b62aa3a4abdf6de3f40a20e1743ab" xml:lang="en">http://git.fedorahosted.org/cgit/sssd.git/commit/?id=30e2585dd46b62aa3a4abdf6de3f40a20e1743ab</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.fedorahosted.org/cgit/sssd.git/commit/?id=2bd514cfde1938b1e245af11c9b548d58d49b325" xml:lang="en">http://git.fedorahosted.org/cgit/sssd.git/commit/?id=2bd514cfde1938b1e245af11c9b548d58d49b325</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0224">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.7"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.6"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.5"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.4"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.3"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.2:beta5"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.2:beta4"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.2:beta3"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.2:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.2:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.1:alpha3"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.1:alpha2"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.1:alpha1"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.0:alpha6"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.0:alpha5"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.0:alpha4"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.0:alpha3"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.0:alpha2"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.0:alpha1"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.x:dev"/>
          <cpe-lang:fact-ref name="cpe:/a:video_project:video:7.x-2.8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:video_project:video:7.x-2.4</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.0:alpha6</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.3</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.2:beta5</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.2:beta3</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.6</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.1:alpha3</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.1:alpha2</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.2:beta4</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.1:alpha1</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.2:beta2</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.5</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.0:alpha2</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.2</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.0:alpha4</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.x:dev</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.0:alpha1</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.7</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.0:alpha5</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.0:alpha3</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.2:beta1</vuln:product>
      <vuln:product>cpe:/a:video_project:video:7.x-2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0224</vuln:cve-id>
    <vuln:published-datetime>2013-03-19T10:55:02.657-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T10:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://drupal.org/node/1896714" xml:lang="en">https://drupal.org/node/1896714</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://drupal.org/node/1895234" xml:lang="en">https://drupal.org/node/1895234</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/25/4" xml:lang="en">[oss-security] 20130124 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:summary>The Video module 7.x-2.x before 7.x-2.9 for Drupal, when using the FFmpeg transcoder, allows local users to execute arbitrary PHP code by modifying a temporary PHP file.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0225">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:rc6"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:rc5"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:rc4"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:rc3"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:rc2"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:rc1"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta10"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta9"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta8"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta7"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta6"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta5"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta4"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta3"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:6.x-1.x:dev"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:7.x-1.0:alpha4"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:7.x-1.0:alpha3"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:7.x-1.0:alpha2"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:7.x-1.0:alpha1"/>
          <cpe-lang:fact-ref name="cpe:/a:user_relationships_project:user_relationships:7.x-1.x:dev"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:7.x-1.x:dev</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.x:dev</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta7</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta4</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta6</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:rc5</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta10</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta2</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta3</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:7.x-1.0:alpha3</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:rc4</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:7.x-1.0:alpha2</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta9</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:rc6</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:rc3</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.3</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta8</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:7.x-1.0:alpha1</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.1</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:7.x-1.0:alpha4</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.2</vuln:product>
      <vuln:product>cpe:/a:user_relationships_project:user_relationships:6.x-1.0:beta5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0225</vuln:cve-id>
    <vuln:published-datetime>2013-03-19T10:55:02.673-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T10:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://drupal.org/node/1896720" xml:lang="en">https://drupal.org/node/1896720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://drupal.org/node/1896276" xml:lang="en">https://drupal.org/node/1896276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://drupal.org/node/1896272" xml:lang="en">https://drupal.org/node/1896272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/25/4" xml:lang="en">[oss-security] 20130124 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupalcode.org/project/user_relationships.git/commitdiff/b9a4739" xml:lang="en">http://drupalcode.org/project/user_relationships.git/commitdiff/b9a4739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupalcode.org/project/user_relationships.git/commitdiff/17e94b9" xml:lang="en">http://drupalcode.org/project/user_relationships.git/commitdiff/17e94b9</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0226">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:zugec_ivan:keyboard_shortcut_utility:7.x-1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zugec_ivan:keyboard_shortcut_utility:7.x-1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0226</vuln:cve-id>
    <vuln:published-datetime>2013-03-19T10:55:02.690-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-21T10:45:15.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T10:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://drupal.org/node/1896752" xml:lang="en">https://drupal.org/node/1896752</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://drupal.org/node/1896752" xml:lang="en">https://drupal.org/node/1896752</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/25/4" xml:lang="en">[oss-security] 20130124 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:summary>The Keyboard Shortcut Utility module 7.x-1.x before 7.x-1.1 for Drupal does not properly check node restrictions, which allows (1) remote authenticated users with the "view shortcuts" permission to read nodes or (2) remote authenticated users with the "admin shortcuts" permission to read, edit, or delete nodes via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0227">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mathijs_koenraadt:search_api_sorts:7.x-1.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mathijs_koenraadt:search_api_sorts:7.x-1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mathijs_koenraadt:search_api_sorts:7.x-1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mathijs_koenraadt:search_api_sorts:7.x-1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mathijs_koenraadt:search_api_sorts:7.x-1.x:dev"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mathijs_koenraadt:search_api_sorts:7.x-1.x:dev</vuln:product>
      <vuln:product>cpe:/a:mathijs_koenraadt:search_api_sorts:7.x-1.3</vuln:product>
      <vuln:product>cpe:/a:mathijs_koenraadt:search_api_sorts:7.x-1.0</vuln:product>
      <vuln:product>cpe:/a:mathijs_koenraadt:search_api_sorts:7.x-1.2</vuln:product>
      <vuln:product>cpe:/a:mathijs_koenraadt:search_api_sorts:7.x-1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0227</vuln:cve-id>
    <vuln:published-datetime>2013-03-19T10:55:02.710-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T10:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://drupal.org/node/1896782" xml:lang="en">https://drupal.org/node/1896782</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://drupal.org/node/1896756" xml:lang="en">https://drupal.org/node/1896756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/25/4" xml:lang="en">[oss-security] 20130124 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupalcode.org/project/search_api_sorts.git/commitdiff/f6cbf47" xml:lang="en">http://drupalcode.org/project/search_api_sorts.git/commitdiff/f6cbf47</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0228">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.42</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.44</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.43</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0228</vuln:cve-id>
    <vuln:published-datetime>2013-03-01T07:37:54.100-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-04T23:40:36.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-04T11:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/torvalds/linux/commit/13d2b4d11d69a92574a55bfd985cfb0ca77aebdc" xml:lang="en">https://github.com/torvalds/linux/commit/13d2b4d11d69a92574a55bfd985cfb0ca77aebdc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=906309" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=906309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1808-1" xml:lang="en">USN-1808-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1805-1" xml:lang="en">USN-1805-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1797-1" xml:lang="en">USN-1797-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1796-1" xml:lang="en">USN-1796-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1795-1" xml:lang="en">USN-1795-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/13/10" xml:lang="en">[oss-security] 20130213 Xen Security Advisory 42 (CVE-2013-0228) - Linux kernel hits general protection if %ds is corrupt for 32-bit PVOPS.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.9" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=13d2b4d11d69a92574a55bfd985cfb0ca77aebdc" xml:lang="en">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=13d2b4d11d69a92574a55bfd985cfb0ca77aebdc</vuln:reference>
    </vuln:references>
    <vuln:summary>The xen_iret function in arch/x86/xen/xen-asm_32.S in the Linux kernel before 3.7.9 on 32-bit Xen paravirt_ops platforms does not properly handle an invalid value in the DS segment register, which allows guest OS users to gain guest OS privileges via a crafted application.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0229">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:miniupnp_project:miniupnpd:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:miniupnp_project:miniupnpd:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:miniupnp_project:miniupnpd:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:miniupnp_project:miniupnpd:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:miniupnp_project:miniupnpd:1.2</vuln:product>
      <vuln:product>cpe:/a:miniupnp_project:miniupnpd:1.1</vuln:product>
      <vuln:product>cpe:/a:miniupnp_project:miniupnpd:1.3</vuln:product>
      <vuln:product>cpe:/a:miniupnp_project:miniupnpd:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0229</vuln:cve-id>
    <vuln:published-datetime>2013-01-31T16:55:01.490-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-01T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-01T14:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://community.rapid7.com/servlet/JiveServlet/download/2150-1-16596/SecurityFlawsUPnP.pdf" xml:lang="en">https://community.rapid7.com/servlet/JiveServlet/download/2150-1-16596/SecurityFlawsUPnP.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-play" xml:lang="en">https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-play</vuln:reference>
    </vuln:references>
    <vuln:summary>The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0230">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:miniupnp_project:miniupnpd:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:miniupnp_project:miniupnpd:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0230</vuln:cve-id>
    <vuln:published-datetime>2013-01-31T16:55:01.520-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-01T14:17:26.863-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-01T14:16:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://community.rapid7.com/servlet/JiveServlet/download/2150-1-16596/SecurityFlawsUPnP.pdf" xml:lang="en">https://community.rapid7.com/servlet/JiveServlet/download/2150-1-16596/SecurityFlawsUPnP.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-play" xml:lang="en">https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-play</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0231">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:3.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:xen:xen:3.0.2</vuln:product>
      <vuln:product>cpe:/o:xen:xen:3.2.2</vuln:product>
      <vuln:product>cpe:/o:xen:xen:3.2.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:xen:xen:3.2.0</vuln:product>
      <vuln:product>cpe:/o:xen:xen:3.0.3</vuln:product>
      <vuln:product>cpe:/o:xen:xen:3.0.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.8</vuln:product>
      <vuln:product>cpe:/o:xen:xen:3.1.3</vuln:product>
      <vuln:product>cpe:/o:xen:xen:3.2.1</vuln:product>
      <vuln:product>cpe:/o:xen:xen:3.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0231</vuln:cve-id>
    <vuln:published-datetime>2013-02-12T20:55:03.497-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-04T23:40:36.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:30:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/81923" xml:lang="en">xen-pcibackenablemsi-dos(81923)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57740" xml:lang="en">57740</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/05/9" xml:lang="en">[oss-security] 20130205 Xen Security Advisory 43 (CVE-2013-0231) - Linux pciback DoS via not rate limited log messages.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2632" xml:lang="en">DSA-2632</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52059" xml:lang="en">52059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/89903" xml:lang="en">89903</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.html" xml:lang="en">SUSE-SU-2013:0674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.html" xml:lang="en">openSUSE-SU-2013:0395</vuln:reference>
    </vuln:references>
    <vuln:summary>The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0232">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:zoneminder:zoneminder:1.24.0"/>
        <cpe-lang:fact-ref name="cpe:/a:zoneminder:zoneminder:1.24.1"/>
        <cpe-lang:fact-ref name="cpe:/a:zoneminder:zoneminder:1.24.2"/>
        <cpe-lang:fact-ref name="cpe:/a:zoneminder:zoneminder:1.24.3"/>
        <cpe-lang:fact-ref name="cpe:/a:zoneminder:zoneminder:1.24.4"/>
        <cpe-lang:fact-ref name="cpe:/a:zoneminder:zoneminder:1.25.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zoneminder:zoneminder:1.24.0</vuln:product>
      <vuln:product>cpe:/a:zoneminder:zoneminder:1.24.4</vuln:product>
      <vuln:product>cpe:/a:zoneminder:zoneminder:1.24.1</vuln:product>
      <vuln:product>cpe:/a:zoneminder:zoneminder:1.25.0</vuln:product>
      <vuln:product>cpe:/a:zoneminder:zoneminder:1.24.3</vuln:product>
      <vuln:product>cpe:/a:zoneminder:zoneminder:1.24.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0232</vuln:cve-id>
    <vuln:published-datetime>2013-03-20T11:55:00.910-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T12:27:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zoneminder.com/forums/viewtopic.php?f=29&amp;t=20771" xml:lang="en">http://www.zoneminder.com/forums/viewtopic.php?f=29&amp;t=20771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/89529" xml:lang="en">89529</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/28/2" xml:lang="en">[oss-security] 20130128 Re: CVE Request: zoneminder: arbitrary command execution vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="http://www.exploit-db.com/exploits/24310" xml:lang="en">24310</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2640" xml:lang="en">DSA-2640</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://itsecuritysolutions.org/2013-01-22-ZoneMinder-Video-Server-arbitrary-command-execution-vulnerability/" xml:lang="en">http://itsecuritysolutions.org/2013-01-22-ZoneMinder-Video-Server-arbitrary-command-execution-vulnerability/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=698910" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=698910</vuln:reference>
    </vuln:references>
    <vuln:summary>includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0233">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:2.2.2"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:2.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:2.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:2.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:2.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:2.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:2.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:2.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:2.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:2.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:1.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:1.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:1.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:plataformatec:devise:1.5.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:novell:opensuse:12.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:plataformatec:devise:1.5.1</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:2.0.0</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:2.2.2</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:2.1.0</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:1.5.3</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:2.2.0</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:2.0.4</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:1.5.0</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:2.0.1</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:2.0.2</vuln:product>
      <vuln:product>cpe:/o:novell:opensuse:12.2</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:2.1.1</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:1.5.2</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:2.0.3</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:2.1.2</vuln:product>
      <vuln:product>cpe:/a:plataformatec:devise:2.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0233</vuln:cve-id>
    <vuln:published-datetime>2013-04-25T19:55:01.460-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-01T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-26T10:12:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://github.com/Snorby/snorby/issues/261" xml:lang="en">https://github.com/Snorby/snorby/issues/261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57577" xml:lang="en">57577</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.phenoelit.org/blog/archives/2013/02/05/mysql_madness_and_rails/index.html" xml:lang="en">http://www.phenoelit.org/blog/archives/2013/02/05/mysql_madness_and_rails/index.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/29/3" xml:lang="en">[oss-security] 20130128 Re: CVE request for 'devise' ruby gem</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.metasploit.com/modules/auxiliary/admin/http/rails_devise_pass_reset" xml:lang="en">http://www.metasploit.com/modules/auxiliary/admin/http/rails_devise_pass_reset</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-03/msg00000.html" xml:lang="en">openSUSE-SU-2013:0374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://blog.plataformatec.com.br/2013/01/security-announcement-devise-v2-2-3-v2-1-3-v2-0-5-and-v1-5-3-released/" xml:lang="en">http://blog.plataformatec.com.br/2013/01/security-announcement-devise-v2-2-3-v2-1-3-v2-0-5-and-v1-5-3-released/</vuln:reference>
    </vuln:references>
    <vuln:summary>Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0238">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:8.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:8.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:8.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:8.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:8.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:7.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:7.3.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:7.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:7.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:7.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:7.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ircd-hybrid:ircd-hybrid:7.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:7.3.0</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:7.2.2</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:8.0.5</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:7.2.3</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:beta1</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:7.2.1</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:8.0.4</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:7.2.0</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:8.0.2</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:8.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:8.0.1</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:7.3.1</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:7.3.0:rc1</vuln:product>
      <vuln:product>cpe:/a:ircd-hybrid:ircd-hybrid:8.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0238</vuln:cve-id>
    <vuln:published-datetime>2013-02-12T20:55:04.090-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-13T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:15:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/81695" xml:lang="en">ircdhybrid-tryparsev4netmask-dos(81695)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57610" xml:lang="en">57610</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/29/8" xml:lang="en">[oss-security] 20130129 ircd-hybrid: Denial of service vulnerability in  hostmask.c:try_parse_v4_netmask()</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2618" xml:lang="en">DSA-2618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.ircd-hybrid.org:8000/viewcvs.cgi/ircd-hybrid/trunk/src/hostmask.c?r1=1786&amp;r2=1785&amp;pathrev=1786" xml:lang="en">http://svn.ircd-hybrid.org:8000/viewcvs.cgi/ircd-hybrid/trunk/src/hostmask.c?r1=1786&amp;r2=1785&amp;pathrev=1786</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52106" xml:lang="en">52106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51948" xml:lang="en">51948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/89623" xml:lang="en">89623</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699267" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699267</vuln:reference>
    </vuln:references>
    <vuln:summary>The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allows remote attackers to cause a denial of service (crash) via a mask that causes a negative number to be parsed.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0239">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.6.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:cxf:2.7.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:cxf:2.6.5</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.5.0</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.6.2</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.5.5</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.5.3</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.5.4</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.5.8</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.6.4</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.4.3</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.4.7</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.7.0</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.4.5</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.4.6</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.7.2</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.6.0</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.5.1</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.5.6</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.5.2</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.4.1</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.4.2</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.6.1</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.5.7</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.4.0</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.7.1</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.4.4</vuln:product>
      <vuln:product>cpe:/a:apache:cxf:2.6.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0239</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T19:55:01.690-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-04T23:40:37.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-19T10:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.apache.org/viewvc?view=revision&amp;revision=1438424" xml:lang="en">http://svn.apache.org/viewvc?view=revision&amp;revision=1438424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/81981" xml:lang="en">apachecxf-username-tokens-sec-bypass(81981)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57876" xml:lang="en">57876</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51988" xml:lang="en">51988</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/fulldisclosure/2013/Feb/39" xml:lang="en">20130208 New security advisories for Apache CXF</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0749.html" xml:lang="en">RHSA-2013:0749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.com/files/120214/Apache-CXF-WS-Security-UsernameToken-Bypass.html" xml:lang="en">http://packetstormsecurity.com/files/120214/Apache-CXF-WS-Security-UsernameToken-Bypass.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/90078" xml:lang="en">90078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cxf.apache.org/cve-2013-0239.html" xml:lang="en">http://cxf.apache.org/cve-2013-0239.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0240">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gnome_online_accounts:3.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gnome_online_accounts:3.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gnome_online_accounts:3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gnome_online_accounts:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gnome_online_accounts:3.6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnome:gnome_online_accounts:3.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gnome_online_accounts:3.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gnome_online_accounts:3.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnome:gnome_online_accounts:3.7.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.04:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:11.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:11.10</vuln:product>
      <vuln:product>cpe:/a:gnome:gnome_online_accounts:3.7.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gnome_online_accounts:3.6.1</vuln:product>
      <vuln:product>cpe:/a:gnome:gnome_online_accounts:3.7.2</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.04:-:lts</vuln:product>
      <vuln:product>cpe:/a:gnome:gnome_online_accounts:3.4.0</vuln:product>
      <vuln:product>cpe:/a:gnome:gnome_online_accounts:3.7.4</vuln:product>
      <vuln:product>cpe:/a:gnome:gnome_online_accounts:3.6.2</vuln:product>
      <vuln:product>cpe:/a:gnome:gnome_online_accounts:3.7.3</vuln:product>
      <vuln:product>cpe:/a:gnome:gnome_online_accounts:3.4.1</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.10</vuln:product>
      <vuln:product>cpe:/a:gnome:gnome_online_accounts:3.6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0240</vuln:cve-id>
    <vuln:published-datetime>2013-04-01T23:22:21.037-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-02T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-02T09:57:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html" xml:lang="en">[gnome-announce-list] 20130304 GNOME Online Accounts 3.6.3 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://git.gnome.org/browse/gnome-online-accounts/commit/?id=edde7c63326242a60a075341d3fea0be0bc4d80e" xml:lang="en">https://git.gnome.org/browse/gnome-online-accounts/commit/?id=edde7c63326242a60a075341d3fea0be0bc4d80e</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://git.gnome.org/browse/gnome-online-accounts/commit/?id=bc10fdb68f75f8be84eb698ada08743b9c7c248f" xml:lang="en">https://git.gnome.org/browse/gnome-online-accounts/commit/?id=bc10fdb68f75f8be84eb698ada08743b9c7c248f</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&amp;id=ecad8142e9ac519b9fc74b96dcb5531052bbffe1" xml:lang="en">https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&amp;id=ecad8142e9ac519b9fc74b96dcb5531052bbffe1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=894352" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=894352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.gnome.org/show_bug.cgi?id=693214" xml:lang="en">https://bugzilla.gnome.org/show_bug.cgi?id=693214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://ubuntu.com/usn/usn-1779-1" xml:lang="en">USN-1779-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52791" xml:lang="en">52791</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51976" xml:lang="en">51976</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-02/msg00046.html" xml:lang="en">openSUSE-SU-2013:0301</vuln:reference>
    </vuln:references>
    <vuln:summary>Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0241">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:qxl_graphics_driver_project:xf86-video-qxl:0.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.04:-:lts"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:11.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_workstation:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:11.10</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_server:6.0</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.04:-:lts</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_workstation:6.0</vuln:product>
      <vuln:product>cpe:/o:qxl_graphics_driver_project:xf86-video-qxl:0.1.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0241</vuln:cve-id>
    <vuln:published-datetime>2013-02-12T20:55:04.137-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-13T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=906032" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=906032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/81704" xml:lang="en">qxl-virtual-spice-dos(81704)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1714-1" xml:lang="en">USN-1714-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/30/4" xml:lang="en">[oss-security] 20130130 Re: CVE request -- qxl: synchronous io guest DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/30/3" xml:lang="en">[oss-security] 20130130 CVE request -- qxl: synchronous io guest DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52021" xml:lang="en">52021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0218.html" xml:lang="en">RHSA-2013:0218</vuln:reference>
    </vuln:references>
    <vuln:summary>The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemu_mutex mutex.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0242">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:glibc:2.17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:glibc:2.17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0242</vuln:cve-id>
    <vuln:published-datetime>2013-02-08T15:55:01.483-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-30T23:22:47.443-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-11T12:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://sourceware.org/bugzilla/show_bug.cgi?id=15078" xml:lang="en">http://sourceware.org/bugzilla/show_bug.cgi?id=15078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/81707" xml:lang="en">glibc-extendbuffers-dos(81707)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id/1028063" xml:lang="en">1028063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57638" xml:lang="en">57638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/01/30/5" xml:lang="en">[oss-security] 20130130 Re: CVE Request -- glibc: DoS due to a buffer overrun in regexp matcher by processing multibyte characters</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://sourceware.org/ml/libc-alpha/2013-01/msg00967.html" xml:lang="en">[libc-alpha] 20130129 [PATCH] Fix buffer overrun in regexp matcher</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51951" xml:lang="en">51951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0769.html" xml:lang="en">RHSA-2013:0769</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/89747" xml:lang="en">89747</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0247">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openstack:essex:2012.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openstack:essex:2012.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openstack:grizzly:-:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:openstack:grizzly:1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.04:-:lts"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.04:-:lts</vuln:product>
      <vuln:product>cpe:/a:openstack:grizzly:1</vuln:product>
      <vuln:product>cpe:/a:openstack:essex:2012.1</vuln:product>
      <vuln:product>cpe:/a:openstack:essex:2012.1.3</vuln:product>
      <vuln:product>cpe:/a:openstack:grizzly:-:rc1</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0247</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T14:55:01.360-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-26T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T14:40:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=906171" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=906171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.launchpad.net/keystone/+bug/1098307" xml:lang="en">https://bugs.launchpad.net/keystone/+bug/1098307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1715-1" xml:lang="en">USN-1715-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57747" xml:lang="en">57747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0253.html" xml:lang="en">RHSA-2013:0253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098906.html" xml:lang="en">FEDORA-2013-2168</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0248">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:commons_fileupload:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:commons_fileupload:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:commons_fileupload:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:commons_fileupload:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:commons_fileupload:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:commons_fileupload:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:commons_fileupload:1.2.1</vuln:product>
      <vuln:product>cpe:/a:apache:commons_fileupload:1.1</vuln:product>
      <vuln:product>cpe:/a:apache:commons_fileupload:1.0</vuln:product>
      <vuln:product>cpe:/a:apache:commons_fileupload:1.2</vuln:product>
      <vuln:product>cpe:/a:apache:commons_fileupload:1.2.2</vuln:product>
      <vuln:product>cpe:/a:apache:commons_fileupload:1.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0248</vuln:cve-id>
    <vuln:published-datetime>2013-03-15T16:55:10.553-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-18T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.3</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-18T13:11:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/90906" xml:lang="en">90906</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2013-03/0035.html" xml:lang="en">20130306 [SECURITY] CVE-2013-0248 Apache Commons FileUpload - Insecure examples</vuln:reference>
    </vuln:references>
    <vuln:summary>The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0249">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu:12.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:haxx:curl:7.26.0"/>
        <cpe-lang:fact-ref name="cpe:/a:haxx:libcurl:7.26.0"/>
        <cpe-lang:fact-ref name="cpe:/a:haxx:curl:7.27.0"/>
        <cpe-lang:fact-ref name="cpe:/a:haxx:libcurl:7.27.0"/>
        <cpe-lang:fact-ref name="cpe:/a:haxx:curl:7.28.0"/>
        <cpe-lang:fact-ref name="cpe:/a:haxx:libcurl:7.28.0"/>
        <cpe-lang:fact-ref name="cpe:/a:haxx:curl:7.28.1"/>
        <cpe-lang:fact-ref name="cpe:/a:haxx:libcurl:7.28.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:haxx:curl:7.28.1</vuln:product>
      <vuln:product>cpe:/a:haxx:libcurl:7.28.1</vuln:product>
      <vuln:product>cpe:/a:haxx:libcurl:7.28.0</vuln:product>
      <vuln:product>cpe:/a:haxx:libcurl:7.26.0</vuln:product>
      <vuln:product>cpe:/a:haxx:curl:7.28.0</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu:12.10</vuln:product>
      <vuln:product>cpe:/a:haxx:libcurl:7.27.0</vuln:product>
      <vuln:product>cpe:/a:haxx:curl:7.27.0</vuln:product>
      <vuln:product>cpe:/a:haxx:curl:7.26.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0249</vuln:cve-id>
    <vuln:published-datetime>2013-03-08T17:55:01.123-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-07T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-18T13:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1721-1" xml:lang="en">USN-1721-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id/1028093" xml:lang="en">1028093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/89988" xml:lang="en">89988</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="http://www.exploit-db.com/exploits/24487" xml:lang="en">24487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.com/files/120170/Slackware-Security-Advisory-curl-Updates.html" xml:lang="en">http://packetstormsecurity.com/files/120170/Slackware-Security-Advisory-curl-Updates.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.com/files/120147/cURL-Buffer-Overflow.html" xml:lang="en">http://packetstormsecurity.com/files/120147/cURL-Buffer-Overflow.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://nakedsecurity.sophos.com/2013/02/10/anatomy-of-a-vulnerability-curl-web-download-toolkit-holed-by-authentication-bug/" xml:lang="en">http://nakedsecurity.sophos.com/2013/02/10/anatomy-of-a-vulnerability-curl-web-download-toolkit-holed-by-authentication-bug/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099140.html" xml:lang="en">FEDORA-2013-2098</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://curl.haxx.se/docs/adv_20130206.html" xml:lang="en">http://curl.haxx.se/docs/adv_20130206.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blog.volema.com/curl-rce.html" xml:lang="en">http://blog.volema.com/curl-rce.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the realm parameter in a (1) POP3, (2) SMTP or (3) IMAP message.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0251">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:debian:latd:1.25"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:latd:1.26"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:latd:1.27"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:latd:1.28"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:latd:1.29"/>
        <cpe-lang:fact-ref name="cpe:/a:debian:latd:1.30"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:debian:latd:1.27</vuln:product>
      <vuln:product>cpe:/a:debian:latd:1.26</vuln:product>
      <vuln:product>cpe:/a:debian:latd:1.25</vuln:product>
      <vuln:product>cpe:/a:debian:latd:1.28</vuln:product>
      <vuln:product>cpe:/a:debian:latd:1.30</vuln:product>
      <vuln:product>cpe:/a:debian:latd:1.29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0251</vuln:cve-id>
    <vuln:published-datetime>2013-03-19T10:55:02.730-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-21T08:00:26.770-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T07:52:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/05/2" xml:lang="en">[oss-security] 20130205 Re: CVE id request: latd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/04/3" xml:lang="en">[oss-security] 20130203 Re: CVE id request: latd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699625" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699625</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in llogincircuit.cc in latd 1.25 through 1.30 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the llogin version.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0252">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:boost:boost:1.48.0"/>
        <cpe-lang:fact-ref name="cpe:/a:boost:boost:1.49.0"/>
        <cpe-lang:fact-ref name="cpe:/a:boost:boost:1.50.0"/>
        <cpe-lang:fact-ref name="cpe:/a:boost:boost:1.51.0"/>
        <cpe-lang:fact-ref name="cpe:/a:boost:boost:1.52.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:boost:boost:1.51.0</vuln:product>
      <vuln:product>cpe:/a:boost:boost:1.49.0</vuln:product>
      <vuln:product>cpe:/a:boost:boost:1.48.0</vuln:product>
      <vuln:product>cpe:/a:boost:boost:1.52.0</vuln:product>
      <vuln:product>cpe:/a:boost:boost:1.50.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0252</vuln:cve-id>
    <vuln:published-datetime>2013-03-12T18:55:01.707-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-18T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-18T16:20:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://svn.boost.org/trac/boost/ticket/7743" xml:lang="en">https://svn.boost.org/trac/boost/ticket/7743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=907481" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=907481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1727-1" xml:lang="en">USN-1727-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57675" xml:lang="en">57675</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/04/2" xml:lang="en">[oss-security] 20130203 Re: CVE id request: boost</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.boost.org/users/news/boost_locale_security_notice.html" xml:lang="en">http://www.boost.org/users/news/boost_locale_security_notice.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099122.html" xml:lang="en">FEDORA-2013-2448</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099103.html" xml:lang="en">FEDORA-2013-2420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699650" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699649" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699649</vuln:reference>
    </vuln:references>
    <vuln:summary>boost::locale::utf::utf_traits in the Boost.Locale library in Boost 1.48 through 1.52 does not properly detect certain invalid UTF-8 sequences, which might allow remote attackers to bypass input validation protection mechanisms via crafted trailing bytes.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0253">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apache:maven:3.0.4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apache:maven_wagon:2.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:maven:3.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0253</vuln:cve-id>
    <vuln:published-datetime>2013-04-09T16:55:01.617-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-10T09:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://maven.apache.org/security.html" xml:lang="en">https://maven.apache.org/security.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=917084" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=917084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0700.html" xml:lang="en">RHSA-2013:0700</vuln:reference>
    </vuln:references>
    <vuln:summary>The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0254">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:1.41"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:1.42"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:1.43"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:1.44"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:1.45"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:3.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:3.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:3.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:3.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:3.3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.6.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.7.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:4.8.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digia:qt:5.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digia:qt:4.5.2</vuln:product>
      <vuln:product>cpe:/a:digia:qt:2.0.0</vuln:product>
      <vuln:product>cpe:/a:digia:qt:5.0.0</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.7.6</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.6.1</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.8.0</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.2.1</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.1.5</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.3.5</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.1.1</vuln:product>
      <vuln:product>cpe:/a:digia:qt:3.3.2</vuln:product>
      <vuln:product>cpe:/a:digia:qt:5.0.1</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.8.5</vuln:product>
      <vuln:product>cpe:/a:digia:qt:1.44</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.5.3</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.1.4</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.0.0</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.7.3</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.5.0</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.7.1</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.6.2</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.2.3</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.6.3</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.1.0</vuln:product>
      <vuln:product>cpe:/a:digia:qt:3.3.6</vuln:product>
      <vuln:product>cpe:/a:digia:qt:3.3.4</vuln:product>
      <vuln:product>cpe:/a:digia:qt:3.3.3</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.3.0</vuln:product>
      <vuln:product>cpe:/a:digia:qt:1.41</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.8.3</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.8.2</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.7.5</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.4.1</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.8.4</vuln:product>
      <vuln:product>cpe:/a:digia:qt:3.3.1</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.6.0</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.8.1</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.5.1</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.6.4</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.1.2</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.4.2</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.3.4</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.2.0</vuln:product>
      <vuln:product>cpe:/a:digia:qt:2.0.2</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.3.3</vuln:product>
      <vuln:product>cpe:/a:digia:qt:2.0.1</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.4.3</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.3.2</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.4.0</vuln:product>
      <vuln:product>cpe:/a:digia:qt:1.42</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.7.0</vuln:product>
      <vuln:product>cpe:/a:digia:qt:3.3.5</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.7.4</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.3.1</vuln:product>
      <vuln:product>cpe:/a:digia:qt:3.3.0</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.7.2</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.6.5</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.1.3</vuln:product>
      <vuln:product>cpe:/a:digia:qt:1.43</vuln:product>
      <vuln:product>cpe:/a:digia:qt:4.0.1</vuln:product>
      <vuln:product>cpe:/a:digia:qt:1.45</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0254</vuln:cve-id>
    <vuln:published-datetime>2013-02-06T07:05:43.647-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-14T23:34:05.970-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-06T14:03:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.qt-project.org/pipermail/announce/2013-February/000023.html" xml:lang="en">[qt-announce] 20130205 [Announce] [CVE-2013-0254] Qt Project Security Advisory: System V shared memory segments created world-writeable</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=907425" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=907425</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0669.html" xml:lang="en">RHSA-2013:0669</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-03/msg00019.html" xml:lang="en">openSUSE-SU-2013:0411</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-03/msg00015.html" xml:lang="en">openSUSE-SU-2013:0404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-03/msg00014.html" xml:lang="en">openSUSE-SU-2013:0403</vuln:reference>
    </vuln:references>
    <vuln:summary>The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0255">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.20"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.19"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.21"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.3.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.13"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.14"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.4.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.1.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:9.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.1.5</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.1.7</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.0.10</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.5</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.15</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.17</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.12</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.8</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.11</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.0.8</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.5</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.0.9</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.14</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.0.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.16</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.7</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.0</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.13</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.8</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.1.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.0.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.0.5</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.21</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.0.7</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.7</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.19</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.0.6</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.9</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.12</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.10</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.1.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.11</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.20</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.9</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.1.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.15</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.14</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.0.11</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.18</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.13</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.6</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.0.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.4.6</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.0.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.1.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.22</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:9.1.6</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.3.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0255</vuln:cve-id>
    <vuln:published-datetime>2013-02-12T20:55:04.590-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-05T23:13:53.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T10:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=907892" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=907892</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://blogs.oracle.com/sunsecurity/entry/cve_2013_0255_array_index" xml:lang="en">https://blogs.oracle.com/sunsecurity/entry/cve_2013_0255_array_index</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/81917" xml:lang="en">postgresql-enumrecv-dos(81917)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1717-1" xml:lang="en">USN-1717-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57844" xml:lang="en">57844</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.postgresql.org/docs/9.2/static/release-9-2-3.html" xml:lang="en">http://www.postgresql.org/docs/9.2/static/release-9-2-3.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.postgresql.org/docs/9.1/static/release-9-1-8.html" xml:lang="en">http://www.postgresql.org/docs/9.1/static/release-9-1-8.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.postgresql.org/docs/9.0/static/release-9-0-12.html" xml:lang="en">http://www.postgresql.org/docs/9.0/static/release-9-0-12.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.postgresql.org/docs/8.4/static/release-8-4-16.html" xml:lang="en">http://www.postgresql.org/docs/8.4/static/release-8-4-16.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.postgresql.org/docs/8.3/static/release-8-3-23.html" xml:lang="en">http://www.postgresql.org/docs/8.3/static/release-8-3-23.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2630" xml:lang="en">DSA-2630</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52819" xml:lang="en">52819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/51923" xml:lang="en">51923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/89935" xml:lang="en">89935</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-02/msg00060.html" xml:lang="en">openSUSE-SU-2013:0319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-02/msg00059.html" xml:lang="en">openSUSE-SU-2013:0318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098586.html" xml:lang="en">FEDORA-2013-2123</vuln:reference>
    </vuln:references>
    <vuln:summary>PostgreSQL 9.2.x before 9.2.3, 9.1.x before 9.1.8, 9.0.x before 9.0.12, 8.4.x before 8.4.16, and 8.3.x before 8.3.23 does not properly declare the enum_recv function in backend/utils/adt/enum.c, which causes it to be invoked with incorrect arguments and allows remote authenticated users to cause a denial of service (server crash) or read sensitive process memory via a crafted SQL command, which triggers an array index error and an out-of-bounds read.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0256">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:dave_thomas:rdoc:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_thomas:rdoc:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:dave_thomas:rdoc:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:1.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:1.9.3:p194"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:1.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:1.9.3:p0"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:1.9.3:p286"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:1.9.3:p125"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:1.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:1.9.3:p383"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:2.0.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:ruby-lang:ruby:2.0.0:rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ruby-lang:ruby:1.9.3:p194</vuln:product>
      <vuln:product>cpe:/a:ruby-lang:ruby:1.9.1</vuln:product>
      <vuln:product>cpe:/a:ruby-lang:ruby:1.9.3</vuln:product>
      <vuln:product>cpe:/a:dave_thomas:rdoc:3.12</vuln:product>
      <vuln:product>cpe:/a:ruby-lang:ruby:1.9.3:p0</vuln:product>
      <vuln:product>cpe:/a:ruby-lang:ruby:2.0.0</vuln:product>
      <vuln:product>cpe:/a:ruby-lang:ruby:2.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:ruby-lang:ruby:1.9.3:p383</vuln:product>
      <vuln:product>cpe:/a:dave_thomas:rdoc:4.0.0</vuln:product>
      <vuln:product>cpe:/a:ruby-lang:ruby:1.9</vuln:product>
      <vuln:product>cpe:/a:ruby-lang:ruby:2.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:dave_thomas:rdoc:2.3.0</vuln:product>
      <vuln:product>cpe:/a:ruby-lang:ruby:1.9.3:p286</vuln:product>
      <vuln:product>cpe:/a:ruby-lang:ruby:1.9.3:p125</vuln:product>
      <vuln:product>cpe:/a:ruby-lang:ruby:2.0</vuln:product>
      <vuln:product>cpe:/a:ruby-lang:ruby:1.9.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0256</vuln:cve-id>
    <vuln:published-datetime>2013-03-01T00:40:17.583-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-04T23:40:39.333-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-01T11:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/rdoc/rdoc/commit/ffa87887ee0517793df7541629a470e331f9fe60" xml:lang="en">https://github.com/rdoc/rdoc/commit/ffa87887ee0517793df7541629a470e331f9fe60</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=907820" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=907820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1733-1" xml:lang="en">USN-1733-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ruby-lang.org/en/news/2013/02/06/rdoc-xss-cve-2013-0256/" xml:lang="en">http://www.ruby-lang.org/en/news/2013/02/06/rdoc-xss-cve-2013-0256/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52774" xml:lang="en">52774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0728.html" xml:lang="en">RHSA-2013:0728</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0701.html" xml:lang="en">RHSA-2013:0701</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0686.html" xml:lang="en">RHSA-2013:0686</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0548.html" xml:lang="en">RHSA-2013:0548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-02/msg00048.html" xml:lang="en">openSUSE-SU-2013:0303</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00015.html" xml:lang="en">SUSE-SU-2013:0647</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blog.segment7.net/2013/02/06/rdoc-xss-vulnerability-cve-2013-0256-releases-3-9-5-3-12-1-4-0-0-rc-2" xml:lang="en">http://blog.segment7.net/2013/02/06/rdoc-xss-vulnerability-cve-2013-0256-releases-3-9-5-3-12-1-4-0-0-rc-2</vuln:reference>
    </vuln:references>
    <vuln:summary>darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0257">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:david_alkire:email2image:6.x-1.x"/>
          <cpe-lang:fact-ref name="cpe:/a:david_alkire:email2image:6.x-2.x"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:david_alkire:email2image:6.x-2.x</vuln:product>
      <vuln:product>cpe:/a:david_alkire:email2image:6.x-1.x</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0257</vuln:cve-id>
    <vuln:published-datetime>2013-03-27T17:55:02.127-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-28T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-28T10:17:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://drupal.org/node/1903264" xml:lang="en">http://drupal.org/node/1903264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/05/1" xml:lang="en">[oss-security] 20130204 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:summary>The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of user email addresses and email fields.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0258">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:google_authenticator_login_project:ga_login:7.x-1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:google_authenticator_login_project:ga_login:7.x-1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:google_authenticator_login_project:ga_login:7.x-1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:google_authenticator_login_project:ga_login:7.x-1.0:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:google_authenticator_login_project:ga_login:7.x-1.0:dev"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:google_authenticator_login_project:ga_login:7.x-1.1</vuln:product>
      <vuln:product>cpe:/a:google_authenticator_login_project:ga_login:7.x-1.0:dev</vuln:product>
      <vuln:product>cpe:/a:google_authenticator_login_project:ga_login:7.x-1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:google_authenticator_login_project:ga_login:7.x-1.0</vuln:product>
      <vuln:product>cpe:/a:google_authenticator_login_project:ga_login:7.x-1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0258</vuln:cve-id>
    <vuln:published-datetime>2013-03-27T17:55:02.143-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-05T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-28T10:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupalcode.org/project/ga_login.git/commitdiff/50b032d" xml:lang="en">http://drupalcode.org/project/ga_login.git/commitdiff/50b032d</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://drupal.org/node/1903282" xml:lang="en">http://drupal.org/node/1903282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/1902102" xml:lang="en">http://drupal.org/node/1902102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/05/1" xml:lang="en">[oss-security] 20130204 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:summary>The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0259">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:boxes_project:boxes:7.x-1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:boxes_project:boxes:7.x-1.0:beta8"/>
          <cpe-lang:fact-ref name="cpe:/a:boxes_project:boxes:7.x-1.0:beta7"/>
          <cpe-lang:fact-ref name="cpe:/a:boxes_project:boxes:7.x-1.0:beta6"/>
          <cpe-lang:fact-ref name="cpe:/a:boxes_project:boxes:7.x-1.0:beta5"/>
          <cpe-lang:fact-ref name="cpe:/a:boxes_project:boxes:7.x-1.0:beta4"/>
          <cpe-lang:fact-ref name="cpe:/a:boxes_project:boxes:7.x-1.0:beta3"/>
          <cpe-lang:fact-ref name="cpe:/a:boxes_project:boxes:7.x-1.0:beta2"/>
          <cpe-lang:fact-ref name="cpe:/a:boxes_project:boxes:7.x-1.0:beta1"/>
          <cpe-lang:fact-ref name="cpe:/a:boxes_project:boxes:7.x-1.x:dev"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:boxes_project:boxes:7.x-1.0:beta2</vuln:product>
      <vuln:product>cpe:/a:boxes_project:boxes:7.x-1.0</vuln:product>
      <vuln:product>cpe:/a:boxes_project:boxes:7.x-1.0:beta3</vuln:product>
      <vuln:product>cpe:/a:boxes_project:boxes:7.x-1.0:beta7</vuln:product>
      <vuln:product>cpe:/a:boxes_project:boxes:7.x-1.0:beta6</vuln:product>
      <vuln:product>cpe:/a:boxes_project:boxes:7.x-1.0:beta4</vuln:product>
      <vuln:product>cpe:/a:boxes_project:boxes:7.x-1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:boxes_project:boxes:7.x-1.0:beta5</vuln:product>
      <vuln:product>cpe:/a:boxes_project:boxes:7.x-1.x:dev</vuln:product>
      <vuln:product>cpe:/a:boxes_project:boxes:7.x-1.0:beta8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0259</vuln:cve-id>
    <vuln:published-datetime>2013-03-27T17:55:02.160-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-28T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-28T10:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://drupal.org/node/1903300" xml:lang="en">http://drupal.org/node/1903300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/05/1" xml:lang="en">[oss-security] 20130204 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupalcode.org/project/boxes.git/commitdiff/456ff8e" xml:lang="en">http://drupalcode.org/project/boxes.git/commitdiff/456ff8e</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/1897016" xml:lang="en">http://drupal.org/node/1897016</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0260">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:elliot_pahl:drush_debian_packaging:-"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:elliot_pahl:drush_debian_packaging:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0260</vuln:cve-id>
    <vuln:published-datetime>2013-03-27T17:55:02.177-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-28T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-28T10:48:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/05/1" xml:lang="en">[oss-security] 20130204 Re: CVE request for Drupal contributed modules</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://drupal.org/node/1903324" xml:lang="en">http://drupal.org/node/1903324</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0261">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openstack:essex:-"/>
        <cpe-lang:fact-ref name="cpe:/a:openstack:folsom:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openstack:folsom:-</vuln:product>
      <vuln:product>cpe:/a:openstack:essex:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0261</vuln:cve-id>
    <vuln:published-datetime>2013-03-08T16:55:01.947-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-18T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-18T11:02:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=908101" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=908101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0595.html" xml:lang="en">RHSA-2013:0595</vuln:reference>
    </vuln:references>
    <vuln:summary>(1) installer/basedefs.py and (2) modules/ospluginutils.py in PackStack allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0262">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rack_project:rack:1.4.3</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.4</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.5.0</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.1</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.5.1</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.0</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0262</vuln:cve-id>
    <vuln:published-datetime>2013-02-08T15:55:01.577-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-14T23:34:06.830-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-11T12:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ" xml:lang="en">https://groups.google.com/forum/#!msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ" xml:lang="en">https://groups.google.com/forum/#!msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/rack/rack/commit/6f237e4c9fab649d3750482514f0fde76c56ab30" xml:lang="en">https://github.com/rack/rack/commit/6f237e4c9fab649d3750482514f0fde76c56ab30</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://github.com/rack/rack/blob/master/lib/rack/file.rb#L56" xml:lang="en">https://github.com/rack/rack/blob/master/lib/rack/file.rb#L56</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://gist.github.com/rentzsch/4736940" xml:lang="en">https://gist.github.com/rentzsch/4736940</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=909072" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=909072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=909071" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=909071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52033" xml:lang="en">52033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://rack.github.com/" xml:lang="en">http://rack.github.com/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html" xml:lang="en">openSUSE-SU-2013:0462</vuln:reference>
    </vuln:references>
    <vuln:summary>rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0263">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rack_project:rack:1.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rack_project:rack:1.3.6</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.1.0</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.1.6</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.1</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.1.4</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.7</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.2</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.0</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.1</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.1</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.5.1</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.9</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.0</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.0</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.4</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.3</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.4.4</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.5</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.6</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.8</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.2</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.4</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.2.3</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.2</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.5.0</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.7</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.1.5</vuln:product>
      <vuln:product>cpe:/a:rack_project:rack:1.3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0263</vuln:cve-id>
    <vuln:published-datetime>2013-02-08T15:55:01.640-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-14T23:34:06.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-11T13:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://twitter.com/coda/statuses/299732877745197056" xml:lang="en">https://twitter.com/coda/statuses/299732877745197056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://groups.google.com/forum/#%21msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ" xml:lang="en">https://groups.google.com/forum/#!msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ" xml:lang="en">https://groups.google.com/forum/#!msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://groups.google.com/forum/#%21msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ" xml:lang="en">https://groups.google.com/forum/#!msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ" xml:lang="en">https://groups.google.com/forum/#!msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J" xml:lang="en">https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11" xml:lang="en">https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07" xml:lang="en">https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://gist.github.com/codahale/f9f3781f7b54985bee94" xml:lang="en">https://gist.github.com/codahale/f9f3781f7b54985bee94</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=909071" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=909071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/89939" xml:lang="en">89939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52774" xml:lang="en">52774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52134" xml:lang="en">52134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52033" xml:lang="en">52033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0686.html" xml:lang="en">RHSA-2013:0686</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://rack.github.com/" xml:lang="en">http://rack.github.com/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html" xml:lang="en">openSUSE-SU-2013:0462</vuln:reference>
    </vuln:references>
    <vuln:summary>Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving am HMAC comparison function that does not run in constant time.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0265">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bitbucket:xnbd:0.1.0:pre"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bitbucket:xnbd:0.1.0:pre</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0265</vuln:cve-id>
    <vuln:published-datetime>2013-02-12T20:55:04.700-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-02-13T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T11:19:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/06/2" xml:lang="en">[oss-security] 20130206 CVE request: Insecure default log file path in xNBD</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/90008" xml:lang="en">90008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/07/5" xml:lang="en">[oss-security] 20130206 Re: CVE request: Insecure default log file path in  xNBD</vuln:reference>
    </vuln:references>
    <vuln:summary>The redirect_stderr function in xnbd_common.c in xnbd-server and xndb-wrapper in xNBD 0.1.0 allow local users to overwrite arbitrary files via a symlink attack on /tmp/xnbd.log.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0266">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openstack:essex:-"/>
        <cpe-lang:fact-ref name="cpe:/a:openstack:folsom:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openstack:folsom:-</vuln:product>
      <vuln:product>cpe:/a:openstack:essex:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0266</vuln:cve-id>
    <vuln:published-datetime>2013-03-08T16:55:01.960-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-18T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-18T11:40:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/puppetlabs/puppetlabs-cinder/commit/7da792fbd40c0e6eae1ee093aa00e0b177bd2ebc" xml:lang="en">https://github.com/puppetlabs/puppetlabs-cinder/commit/7da792fbd40c0e6eae1ee093aa00e0b177bd2ebc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=908581" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=908581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0595.html" xml:lang="en">RHSA-2013:0595</vuln:reference>
    </vuln:references>
    <vuln:summary>manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading the files.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0268">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.2.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.4.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.5.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:3.7.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.42</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.3.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.5.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.44</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.43</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.1.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.2.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.4.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.7.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:3.0:rc7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0268</vuln:cve-id>
    <vuln:published-datetime>2013-02-17T23:41:50.417-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-04T23:40:40.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-18T11:44:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c903f0456bc69176912dee6dd25c6a66ee1aed00" xml:lang="en">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c903f0456bc69176912dee6dd25c6a66ee1aed00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/torvalds/linux/commit/c903f0456bc69176912dee6dd25c6a66ee1aed00" xml:lang="en">https://github.com/torvalds/linux/commit/c903f0456bc69176912dee6dd25c6a66ee1aed00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=908693" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=908693</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/07/12" xml:lang="en">[oss-security] 20130207 Re: CVE request -- Linux kernel: x86/msr: /dev/cpu/*/msr local privilege escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.6" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.html" xml:lang="en">SUSE-SU-2013:0674</vuln:reference>
    </vuln:references>
    <vuln:summary>The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0269">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubygems:json_gem:1.5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rubygems:json_gem:1.5.2</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.7.3</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.6.6</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.5.1</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.6.3</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.7.1</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.6.1</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.6.2</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.5.3</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.7.5</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.6.5</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.6.4</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.7.4</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.5.0</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.5.4</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.7.0</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.7.6</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.6.7</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.7.2</vuln:product>
      <vuln:product>cpe:/a:rubygems:json_gem:1.6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0269</vuln:cve-id>
    <vuln:published-datetime>2013-02-12T20:55:05.107-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-04T23:40:40.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T13:03:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://groups.google.com/group/rubyonrails-security/msg/d8e0db6e08c81428?dmode=source&amp;output=gplain" xml:lang="en">[rubyonrails-security] 20130211 Denial of Service and Unsafe Object Creation Vulnerability in JSON [CVE-2013-0269]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/82010" xml:lang="en">json-ruby-security-bypass(82010)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zweitag.de/en/blog/ruby-on-rails-vulnerable-to-mass-assignment-and-sql-injection" xml:lang="en">http://www.zweitag.de/en/blog/ruby-on-rails-vulnerable-to-mass-assignment-and-sql-injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1733-1" xml:lang="en">USN-1733-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/57899" xml:lang="en">57899</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/90074" xml:lang="en">90074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/11/8" xml:lang="en">[oss-security] 20130211 Patch update for [CVE-2013-0269]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/11/7" xml:lang="en">[oss-security] 20130211 Denial of Service and Unsafe Object Creation Vulnerability in JSON [CVE-2013-0269]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/" xml:lang="en">http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed" xml:lang="en">http://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52902" xml:lang="en">52902</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52774" xml:lang="en">52774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/52075" xml:lang="en">52075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0701.html" xml:lang="en">RHSA-2013:0701</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0686.html" xml:lang="en">RHSA-2013:0686</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-updates/2013-04/msg00034.html" xml:lang="en">openSUSE-SU-2013:0603</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00015.html" xml:lang="en">SUSE-SU-2013:0647</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00001.html" xml:lang="en">SUSE-SU-2013:0609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2013-03/0104.html" xml:lang="en">SSA:2013-075-01</vuln:reference>
    </vuln:references>
    <vuln:summary>The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-0270">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openstack:folsom:2012.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openstack:folsom:2012.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openstack:grizzly:2012.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openstack:grizzly:2012.2</vuln:product>
      <vuln:product>cpe:/a:openstack:folsom:2012.2</vuln:product>
      <vuln:product>cpe:/a:openstack:folsom:2012.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0270</vuln:cve-id>
    <vuln:published-datetime>2013-04-12T18:55:01.070-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-04-15T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-15T10:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://launchpad.net/keystone/grizzly/2013.1" xml:lang="en">https://launchpad.net/keystone/grizzly/2013.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/openstack/keystone/commit/82c87e5638ebaf9f166a9b07a0155291276d6fdc" xml:lang="en">https://github.com/openstack/keystone/commit/82c87e5638ebaf9f166a9b07a0155291276d6fdc</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/openstack/keystone/commit/7691276b869a86c2b75631d5bede9f61e030d9d8" xml:lang="en">https://github.com/openstack/keystone/commit/7691276b869a86c2b75631d5bede9f61e030d9d8</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=909012" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=909012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.launchpad.net/keystone/+bug/1099025" xml:lang="en">https://bugs.launchpad.net/keystone/+bug/1099025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0708.html" xml:lang="en">RHSA-2013:0708</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenStack Keystone Grizzly before 2013.1, Folsom, and possibly earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a large HTTP request, as demonstrated by a long tenant_name when requesting a token.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0271">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.11"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.8"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.10"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.9"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.8</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.1.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.0.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.3.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.2.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.10</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.0.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.9</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.8</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.11</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.3.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.9.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.2.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.7</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.9</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.8.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.2.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.7</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.0.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.1.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0271</vuln:cve-id>
    <vuln:published-datetime>2013-02-16T16:55:02.093-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-22T23:15:13.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-18T10:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1746-1" xml:lang="en">USN-1746-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.pidgin.im/news/security/?id=65" xml:lang="en">http://www.pidgin.im/news/security/?id=65</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00006.html" xml:lang="en">openSUSE-SU-2013:0405</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00003.html" xml:lang="en">SUSE-SU-2013:0388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://hg.pidgin.im/pidgin/main/rev/a8aef1d340f2" xml:lang="en">http://hg.pidgin.im/pidgin/main/rev/a8aef1d340f2</vuln:reference>
    </vuln:references>
    <vuln:summary>The MXit protocol plugin in libpurple in Pidgin before 2.10.7 might allow remote attackers to create or overwrite files via a crafted (1) mxit or (2) mxit/imagestrips pathname.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0272">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.11"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.8"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.10"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.9"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.8</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.1.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.0.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.3.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.2.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.10</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.0.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.9</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.8</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.11</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.3.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.9.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.2.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.7</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.9</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.8.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.2.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.7</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.0.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.1.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0272</vuln:cve-id>
    <vuln:published-datetime>2013-02-16T16:55:02.153-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-22T23:15:13.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-18T10:50:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1746-1" xml:lang="en">USN-1746-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.pidgin.im/news/security/?id=66" xml:lang="en">http://www.pidgin.im/news/security/?id=66</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00007.html" xml:lang="en">openSUSE-SU-2013:0407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00006.html" xml:lang="en">openSUSE-SU-2013:0405</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00003.html" xml:lang="en">SUSE-SU-2013:0388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://hg.pidgin.im/pidgin/main/rev/879db2a9a59c" xml:lang="en">http://hg.pidgin.im/pidgin/main/rev/879db2a9a59c</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code via a long HTTP header.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0273">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.11"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.8"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.10"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.9"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.8</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.1.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.0.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.3.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.2.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.10</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.0.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.9</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.8</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.11</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.3.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.9.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.2.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.7</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.9</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.8.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.2.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.7</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.0.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.1.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0273</vuln:cve-id>
    <vuln:published-datetime>2013-02-16T16:55:02.233-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-22T23:15:13.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-18T10:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1746-1" xml:lang="en">USN-1746-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.pidgin.im/news/security/?id=67" xml:lang="en">http://www.pidgin.im/news/security/?id=67</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00007.html" xml:lang="en">openSUSE-SU-2013:0407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00006.html" xml:lang="en">openSUSE-SU-2013:0405</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00003.html" xml:lang="en">SUSE-SU-2013:0388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://hg.pidgin.im/pidgin/main/rev/c31cf8de31cd" xml:lang="en">http://hg.pidgin.im/pidgin/main/rev/c31cf8de31cd</vuln:reference>
    </vuln:references>
    <vuln:summary>sametime.c in the Sametime protocol plugin in libpurple in Pidgin before 2.10.7 does not properly terminate long user IDs, which allows remote servers to cause a denial of service (application crash) via a crafted packet.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0274">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.11"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.8"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.10"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.9"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:pidgin:pidgin:2.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.8</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.1.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.0.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.3.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.2.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.10</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.0.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.6.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.9</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.8</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.6</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.11</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.3.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.3</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.9.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.2.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.7</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.5</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.4</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.9</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.8.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.4.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.2.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.7.7</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.0.2</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.5.1</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.1.0</vuln:product>
      <vuln:product>cpe:/a:pidgin:pidgin:2.10.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0274</vuln:cve-id>
    <vuln:published-datetime>2013-02-16T16:55:02.280-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-22T23:15:13.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.9</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-18T11:04:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1746-1" xml:lang="en">USN-1746-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.pidgin.im/news/security/?id=68" xml:lang="en">http://www.pidgin.im/news/security/?id=68</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00007.html" xml:lang="en">openSUSE-SU-2013:0407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00006.html" xml:lang="en">openSUSE-SU-2013:0405</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00003.html" xml:lang="en">SUSE-SU-2013:0388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://hg.pidgin.im/pidgin/main/rev/ad7e7fb98db3" xml:lang="en">http://hg.pidgin.im/pidgin/main/rev/ad7e7fb98db3</vuln:reference>
    </vuln:references>
    <vuln:summary>upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0275">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:2.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:2.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:2.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:3.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:3.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ganglia:ganglia-web:3.5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ganglia:ganglia-web:3.4.2</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:3.5.3</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:3.3.0</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:2.1.1</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:3.3.1</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:3.4.1</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:3.5.2</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:2.1.0</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:3.5.4</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:2.2.0</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:2.1.3</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:3.5.1</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:2.1.8</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:2.1.2</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:3.5.5</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:2.1.6</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:3.5.0</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:2.1.5</vuln:product>
      <vuln:product>cpe:/a:ganglia:ganglia-web:2.1.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0275</vuln:cve-id>
    <vuln:published-datetime>2013-03-13T23:12:47.400-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-03-19T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-19T13:18:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/ganglia/ganglia-web/commit/31d348947419058c43b8dfcd062e2988abd5058e" xml:lang="en">https://github.com/ganglia/ganglia-web/commit/31d348947419058c43b8dfcd062e2988abd5058e</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=892823" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=892823</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/58204" xml:lang="en">58204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/08/6" xml:lang="en">[oss-security] 20130208 Re: CVE request: XSS flaws fixed in ganglia</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ganglia.info/?p=566" xml:lang="en">http://ganglia.info/?p=566</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Ganglia Web before 3.5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0276">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.15</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.14</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.12</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.16</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.5:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.13</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.4:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.11</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.2:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.11</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.4:rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0276</vuln:cve-id>
    <vuln:published-datetime>2013-02-12T20:55:05.167-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-06-05T23:24:30.627-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T12:43:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/02/11/5" xml:lang="en">[oss-security] 20130211 Circumvention of attr_protected [CVE-2013-0276]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://groups.google.com/group/rubyonrails-security/msg/bb44b98a73ef