<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" nvd_xml_version="2.0" pub_date="2009-11-07T06:05:00" xsi:schemaLocation="http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
    <entry id="CVE-1999-1395">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.1b" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.2" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.3" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.4" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:dec:dec_openvms:5.4</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.1.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.1.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.4.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.0</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.2.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.3</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.4.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.1b</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.0.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.0.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.3.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1395</vuln:cve-id>
        <vuln:published-datetime>1992-11-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T00:02:35.750-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-92.16.VMS.Monitor.vulnerability">CA-92.16</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1992-18.html">CA-1992-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/51">51</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7136.php">vms-monitor-gain-privileges(7136)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59332">59332</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0593">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0593</vuln:cve-id>
        <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T00:01:02.017-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/1291">nt-shutdown-without-logon(1291)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true">http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://technet.microsoft.com/en-us/library/cc722469.aspx">http://technet.microsoft.com/en-us/library/cc722469.aspx</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59333">59333</vuln:reference>
        </vuln:references>
        <vuln:summary>The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0498">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:intersystems:cache_database:5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0498</vuln:cve-id>
        <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-07T00:18:20.420-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-94" />
        <vuln:summary>Cach�Ã�© Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0497">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:intersystems:cache_database:5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0497</vuln:cve-id>
        <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-07T00:18:19.750-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:summary>Cach�Ã�© Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.</vuln:summary>
    </entry>
    <entry id="CVE-2005-1921">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc1" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc2" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc3" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc4" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc5" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc6" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc7" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.3.0rc1" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.3.0rc2" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.3.0rc3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:pear:xml_rpc:1.0.4</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc7</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.0.2</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.0.3</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc3</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.3.0rc1</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc4</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.3.0rc2</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc5</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.3.0rc3</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc6</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.2</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc2</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.1</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc1</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-1921</vuln:cve-id>
        <vuln:published-datetime>2005-07-05T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-07T00:40:39.670-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-07-05T11:58:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:350" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:350" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:109">MDKSA-2005:109</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gulftech.org/?node=research&amp;article_id=00087-07012005">http://www.gulftech.org/?node=research&amp;article_id=00087-07012005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://pear.php.net/package/XML_RPC/download/1.3.1">http://pear.php.net/package/XML_RPC/download/1.3.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112008638320145&amp;w=2">20050629 Advisory 02/2005: Remote code execution in Serendipity</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/419064/100/0/threaded">HPSBTU02083</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.hardened-php.net/advisory-022005.php">http://www.hardened-php.net/advisory-022005.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/14088">14088</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/419064/100/0/threaded">SSRT051069</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-564.html">RHSA-2005:564</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_49_php.html">SUSE-SA:2005:049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_41_php_pear.html">SUSE-SA:2005:041</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/2827">ADV-2005-2827</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt">http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-789">DSA-789</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-747">DSA-747</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-746">DSA-746</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-745">DSA-745</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ampache.org/announce/3_3_1_2.php">http://www.ampache.org/announce/3_3_1_2.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=338803">http://sourceforge.net/project/shownotes.php?release_id=338803</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/showfiles.php?group_id=87163">http://sourceforge.net/project/showfiles.php?group_id=87163</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015336">1015336</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200507-07.xml">GLSA-200507-07</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200507-06.xml">GLSA-200507-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200507-01.xml">GLSA-200507-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18003">18003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17674">17674</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17440">17440</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/16693">16693</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/16339">16339</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/16001">16001</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15957">15957</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15947">15947</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15944">15944</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15922">15922</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15917">15917</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15916">15916</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15904">15904</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15903">15903</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15895">15895</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15884">15884</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15883">15883</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15872">15872</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15861">15861</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15855">15855</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15852">15852</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15810">15810</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2">SUSE-SA:2005:051</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112015336720867&amp;w=2">20050629 [DRUPAL-SA-2005-003] Drupal 4.6.2 / 4.5.4 fixes critical XML-RPC issue</vuln:reference>
        </vuln:references>
        <vuln:summary>Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.</vuln:summary>
    </entry>
    <entry id="CVE-2005-1689">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3.5" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3.6" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.4" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3.2</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3.1</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.4.1</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3.3</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3.4</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3.5</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3.6</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-1689</vuln:cve-id>
        <vuln:published-datetime>2005-07-18T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-29T00:38:07.547-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-07-18T09:53:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/623332">VU#623332</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200507-11.xml">GLSA-200507-11</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-757">DSA-757</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/21055">kerberos-kdc-krb5recvauth-execute-code(21055)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-224-1">USN-224-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TURBO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.turbolinux.com/security/2005/TLSA-2005-78.txt">TLSA-2005-78</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2005/0036">2005-0036</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/14239">14239</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-567.html">RHSA-2005:567</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-562.html">RHSA-2005:562</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_17_sr.html">SUSE-SR:2005:017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3776">ADV-2006-3776</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/1066">ADV-2005-1066</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txt">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101810-1">101810</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1014461">1014461</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22090">22090</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17899">17899</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17135">17135</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/16041">16041</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112119974704542&amp;w=2">20050712 MITKRB5-SA-2005-003: double-free in krb5_recvauth</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000993">CLA-2005:993</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.asc">20050703-01-U</vuln:reference>
        </vuln:references>
        <vuln:summary>Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.</vuln:summary>
    </entry>
    <entry id="CVE-2005-2491">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:pcre:pcre:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:pcre:pcre:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:pcre:pcre:6.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:pcre:pcre:5.0</vuln:product>
            <vuln:product>cpe:/a:pcre:pcre:6.0</vuln:product>
            <vuln:product>cpe:/a:pcre:pcre:6.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-2491</vuln:cve-id>
        <vuln:published-datetime>2005-08-23T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-01T00:46:24.170-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-08-23T10:18:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:735" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:735" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1659" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1659" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1496" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1496" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1014744">1014744</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/14620">14620</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/15647">15647</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/427046/100/0/threaded">FLSA:168516</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2006-0197.html">RHSA-2006:0197</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-761.html">RHSA-2005:761</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-358.html">RHSA-2005:358</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/release_4_4_1.php">http://www.php.net/release_4_4_1.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_52_apache2.html">SUSE-SA:2005:052</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_49_php.html">SUSE-SA:2005:049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_48_pcre.html">SUSE-SA:2005:048</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200509-19.xml">GLSA-200509-19</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200509-12.xml">GLSA-200509-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200509-02.xml">GLSA-200509-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200508-17.xml">GLSA-200509-08</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4502">ADV-2006-4502</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4320">ADV-2006-4320</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/2659">ADV-2005-2659</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/1511">ADV-2005-1511</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ethereal.com/appnotes/enpa-sa-00021.html">http://www.ethereal.com/appnotes/enpa-sa-00021.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-821">DSA-821</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-819">DSA-819</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-817">DSA-817</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-800">DSA-800</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-159.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-159.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/604">604</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22875">22875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22691">22691</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21522">21522</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19532">19532</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19193">19193</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19072">19072</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17813">17813</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17252">17252</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/16679">16679</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/16502">16502</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112606064317223&amp;w=2">OpenPKG-SA-2005.018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2">SUSE-SA:2005:051</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html">TSLSA-2005-0059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522">SSRT061238</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=302847">APPLE-SA-2005-11-29</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U">20060401-01-U</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SCO</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txt">SCOSA-2006.10</vuln:reference>
        </vuln:references>
        <vuln:summary>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</vuln:summary>
    </entry>
    <entry id="CVE-2005-4209">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:8.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:alt-n:worldclient:8.1.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:alt-n:worldclient:8.1.3</vuln:product>
            <vuln:product>cpe:/a:alt-n:mdaemon:8.1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-4209</vuln:cve-id>
        <vuln:published-datetime>2005-12-13T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T00:54:01.500-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.1</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-12-13T10:36:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/23551">mdaemon-worldclient-subject-dos(23551)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/15815">15815</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ipomonis.com/advisories/mdaemon.zip">http://www.ipomonis.com/advisories/mdaemon.zip</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17990">17990</vuln:reference>
        </vuln:references>
        <vuln:summary>WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability.</vuln:summary>
    </entry>
    <entry id="CVE-2005-3352">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.10" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.11" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.11::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.12" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.12::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.13" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.13::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.14" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.14::mac_os" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.14::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.15" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.15::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.16" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.16::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.17" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.17::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.18" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.18::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.19" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.19::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.20" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.20::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.22" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.22::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.23" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.23::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.24" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.24::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.25" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.25::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.26" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.26::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.27" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.28" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.29" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.30" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.31" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.5" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.6" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.7" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.7::dev" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.8" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.9" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28:beta" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28:beta:win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32:beta:win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.34:beta:win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.49" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.50" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.51" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.52" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.53" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.54" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.55" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:apache:mod_imap" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:2.0.32:beta:win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.17::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.23::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.55</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.18</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.17</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.18::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.14::mac_os</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.19</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.14</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.25::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.19::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.13</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.16</vuln:product>
            <vuln:product>cpe:/a:apache:mod_imap</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.15</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.10</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.12</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.50</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.11</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.51</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.52</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.53</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.54</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.9</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.15::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.34:beta:win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.13::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.14::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.49</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.24::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.16::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28:beta:win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.9</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.8</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.30</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.7</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.6</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.11::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.31</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.7::dev</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.26::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.27</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.26</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.25</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.24</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28:beta</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.29</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.28</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.20::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.22::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.12::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.23</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.22</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.20</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-3352</vuln:cve-id>
        <vuln:published-datetime>2005-12-13T15:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:41:31.233-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-12-14T10:33:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA08-150A.html">TA08-150A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015344">1015344</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:007">MDKSA-2006:007</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/usn/usn-241-1">USN-241-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2005/0074/">TSLSA-2005-0074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/15834">15834</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450321/100/0/threaded">SSRT061265</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/425399/100/0/threaded">FLSA-2006:175406</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2006-0158.html">RHSA-2006:0158</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00060.html">FEDORA-2006-052</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.org/security/OpenPKG-SA-2005.029-apache.txt">OpenPKG-SA-2005.029</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200602-03.xml">GLSA-200602-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/2870">ADV-2005-2870</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK16139&amp;apar=only">PK16139</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19012">19012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18743">18743</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18585">18585</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18526">18526</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18517">18517</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18429">18429</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18340">18340</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18339">18339</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18333">18333</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18008">18008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17319">17319</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2006-0159.html">RHSA-2006:0159</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html">SUSE-SR:2006:004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://issues.apache.org/bugzilla/show_bug.cgi?id=37874">http://issues.apache.org/bugzilla/show_bug.cgi?id=37874</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U">20060101-01-U</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450321/100/0/threaded">SSRT061265</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450315/100/0/threaded">HPSBUX02172</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">SSRT061202</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_43_apache.html">SUSE-SA:2006:043</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1697">ADV-2008-1697</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1246/references">ADV-2008-1246</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4868">ADV-2006-4868</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4300">ADV-2006-4300</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4015">ADV-2006-4015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3995">ADV-2006-3995</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/2423">ADV-2006-2423</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1167">DSA-1167</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK25355&amp;apar=only">PK25355</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1">102663</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1">102662</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.685483">SSA:2006-129-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.470158">SSA:2006-130-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30430">30430</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29849">29849</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29420">29420</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25239">25239</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23260">23260</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22669">22669</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22388">22388</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22368">22368</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22140">22140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21744">21744</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/20670">20670</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/20046">20046</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2006-0692.html">RHSA-2006:0692</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html">SUSE-SR:2007:011</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html">APPLE-SA-2008-05-28</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449">SSRT071293</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.</vuln:summary>
    </entry>
    <entry id="CVE-2005-4265">
        <vuln:cve-id>CVE-2005-4265</vuln:cve-id>
        <vuln:published-datetime>2005-12-15T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T00:54:22.077-04:00</vuln:last-modified-datetime>
        <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4209.  Reason: This candidate is a duplicate of CVE-2005-4209.  Notes: All CVE users should reference CVE-2005-4209 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
    </entry>
    <entry id="CVE-2006-3918">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.11::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.12" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.12::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.17" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.18" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.19" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.20" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.22" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.57" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:http_server:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:http_server:6.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:http_server:6.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.18</vuln:product>
            <vuln:product>cpe:/a:ibm:http_server:6.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.17</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.57</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.19</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.12</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.11::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.12::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.22</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.20</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-3918</vuln:cve-id>
        <vuln:published-datetime>2006-07-27T20:04:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T01:17:06.610-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-07-31T15:50:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/2964">ADV-2006-2964</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/2963">ADV-2006-2963</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21174">21174</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21172">21172</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2006-0619.html">RHSA-2006:0619</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3264">ADV-2006-3264</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg24013080">PK27875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg1PK24631">PK24631</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://svn.apache.org/viewvc?view=rev&amp;revision=394965">http://svn.apache.org/viewvc?view=rev&amp;revision=394965</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1016569">1016569</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21478">21478</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21399">21399</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2006-0618.html">RHSA-2006:0618</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/bugtraq/2006-07/0425.html">20060724 Write-up by Amit Klein: "Forging HTTP request headers with Flash"</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/bugtraq/2006-05/0151.html">20060508 Unfiltered Header Injection in Apache 1.3.34/2.0.57/2.2.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-575-1">USN-575-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/19661">19661</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_51_apache.html">SUSE-SA:2006:051</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/5089">ADV-2006-5089</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4207">ADV-2006-4207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1167">DSA-1167</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-194.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-194.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/1294">1294</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29640">29640</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28749">28749</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22523">22523</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22317">22317</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22140">22140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21986">21986</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21848">21848</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21744">21744</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21598">21598</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2006-0692.html">RHSA-2006:0692</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENBSD</vuln:source>
            <vuln:reference xml:lang="en" href="http://openbsd.org/errata.html#httpd2">[3.9] 012: SECURITY FIX: October 7, 2006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html">SUSE-SA:2008:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://kb.vmware.com/KanisaPlatform/Publishing/466/5915871_f.SAL_Public.html">http://kb.vmware.com/KanisaPlatform/Publishing/466/5915871_f.SAL_Public.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P">20060801-01-P</vuln:reference>
        </vuln:references>
        <vuln:summary>http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.</vuln:summary>
    </entry>
    <entry id="CVE-2006-3747">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.28" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.29" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.30" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.31" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.33" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.5" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.6" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.7" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.7::dev" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.8" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.9" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.49" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.50" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.51" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.52" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.53" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.54" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.55" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.56" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.57" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.58" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.06_lts" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.55</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.56</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.57</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.58</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.9</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.8</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.7</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.30</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.6</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.50</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.51</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.31</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.52</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.7::dev</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.53</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.33</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.54</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.06_lts</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.29</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.28</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.49</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-3747</vuln:cve-id>
        <vuln:published-datetime>2006-07-28T14:02:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T00:47:03.577-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.6</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-07-31T16:54:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-189" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/395412">VU#395412</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA08-150A.html">TA08-150A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1132">DSA-1132</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1131">DSA-1131</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.apache.org/dist/httpd/Announcement2.0.html">http://www.apache.org/dist/httpd/Announcement2.0.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-538">https://issues.rpath.com/browse/RPL-538</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/28063">apache-modrewrite-offbyone-bo(28063)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-328-1">USN-328-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/19204">19204</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450321/100/0/threaded">HPSBUX02164</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/443870/100/0/threaded">20060820 POC &amp; exploit for Apache mod_rewrite off-by-one</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/441526/100/200/threaded">20060728 rPSA-2006-0139-1 httpd mod_ssl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/441487/100/0/threaded">20060728 Apache mod_rewrite Buffer Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/441485/100/0/threaded">20060728 [Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/27588">27588</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.015-apache.html">OpenPKG-SA-2006.015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_43_apache.html">SUSE-SA:2006:043</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4015">ADV-2006-4015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3995">ADV-2006-3995</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3884">ADV-2006-3884</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3282">ADV-2006-3282</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3264">ADV-2006-3264</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3017">ADV-2006-3017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg24013080">PK27875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg1PK29156">PK29156</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg1PK29154">PK29154</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://svn.apache.org/viewvc?view=rev&amp;revision=426144">http://svn.apache.org/viewvc?view=rev&amp;revision=426144</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1">102663</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1">102662</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1016601">1016601</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200608-01.xml">GLSA-200608-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22388">22388</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22368">22368</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22262">22262</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21509">21509</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21478">21478</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21315">21315</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21313">21313</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21307">21307</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21284">21284</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21273">21273</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21266">21266</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21247">21247</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21245">21245</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21241">21241</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21197">21197</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048271.html">20060728 [Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048267.html">20060728 Apache 1.3.29/2.X mod_rewrite Buffer Overflow Vulnerability CVE-2006-3747</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://kbase.redhat.com/faq/FAQ_68_8653.shtm">http://kbase.redhat.com/faq/FAQ_68_8653.shtm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:133">MDKSA-2006:133</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450321/100/0/threaded">HPSBUX02164</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:133">MDKSA-2006:133</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1697">ADV-2008-1697</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1246/references">ADV-2008-1246</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/2783">ADV-2007-2783</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4868">ADV-2006-4868</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4300">ADV-2006-4300</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4207">ADV-2006-4207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg27007951">http://www-1.ibm.com/support/docview.wss?uid=swg27007951</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/1312">1312</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30430">30430</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29849">29849</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29420">29420</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26329">26329</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23260">23260</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23028">23028</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22523">22523</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21346">21346</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://lwn.net/Alerts/194228/">2006-0044</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html">APPLE-SA-2008-05-28</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449">HPSBMA02328</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771">SSRT061275</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
        </vuln:references>
        <vuln:summary>Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.</vuln:summary>
    </entry>
    <entry id="CVE-2006-4339">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7a" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7b" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7c" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7d" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7e" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7f" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7g" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7h" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7i" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7j" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8a" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8b" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6f" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6i" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6k" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6j" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6l" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6b" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a:beta3" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6:beta3" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.3a" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.4" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.3" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.2b" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.1c" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6m" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openssl:openssl:0.9.3</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.4</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.8</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6a</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6b</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.1c</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.8b</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.8a</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6a:beta1</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6f</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6a:beta3</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6a:beta2</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6:beta1</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6:beta2</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6:beta3</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7j</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7i</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7h</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7g</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7f</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7e</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7d</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7c</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7b</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5:beta2</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7a</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.2b</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5:beta1</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5a</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.3a</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6m</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6k</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5a:beta2</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5a:beta1</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6l</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6i</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6j</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-4339</vuln:cve-id>
        <vuln:published-datetime>2006-09-05T13:04:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-03T01:10:43.750-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.1</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-09-05T13:17:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-310" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/845620">VU#845620</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA06-333A.html">TA06-333A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us.debian.org/security/2006/dsa-1173">DSA-1173</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-339-1">USN-339-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/19849">19849</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openssl.org/news/secadv_20060905.txt">http://www.openssl.org/news/secadv_20060905.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3453">ADV-2006-3453</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1174">DSA-1174</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21709">21709</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-616">https://issues.rpath.com/browse/RPL-616</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/28755">openssl-rsa-security-bypass(28755)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445822/100/0/threaded">20060912 ERRATA: [ GLSA 200609-05 ] OpenSSL, AMD64 x86 emulation base libraries: RSA signature forgery</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445231/100/0/threaded">20060905 rPSA-2006-0163-1 openssl openssl-scripts</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0629.html">RHSA-2008:0629</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2006-0661.html">RHSA-2006:0661</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/28549">28549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.opera.com/support/search/supsearch.dml?index=845">http://www.opera.com/support/search/supsearch.dml?index=845</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENBSD</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openbsd.org/errata.html">[3.9] 20060908 011: SECURITY FIX: September 8, 2006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_55_ssl.html">SUSE-SA:2006:055</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/">http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:161">MDKSA-2006:161</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.imc.org/ietf-openpgp/mail-archive/msg14307.html">[ietf-openpgp] 20060827 Bleichenbacher's RSA signature forgery based on implementation error</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3793">ADV-2006-3793</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3730">ADV-2006-3730</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3566">ADV-2006-3566</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-188.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-188.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.605306">SSA:2006-257-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1016791">1016791</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200609-18.xml">GLSA-200609-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200609-05.xml">GLSA-200609-05</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.freebsd.org/advisories/FreeBSD-SA-06:19.openssl.asc">FreeBSD-SA-06:19</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31492">31492</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22259">22259</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22161">22161</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22036">22036</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21982">21982</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21930">21930</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21927">21927</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21906">21906</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21873">21873</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21870">21870</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21852">21852</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21846">21846</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21823">21823</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21812">21812</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21791">21791</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21785">21785</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21778">21778</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21776">21776</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21767">21767</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771">HPSBMA02250</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495">SSRT061273</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:178">MDKSA-2006:178</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:177">MDKSA-2006:177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc">20060901-01-P</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://secure-support.novell.com/KanisaPlatform/Publishing/41/3143224_f.SAL_Public.html">https://secure-support.novell.com/KanisaPlatform/Publishing/41/3143224_f.SAL_Public.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-1633">https://issues.rpath.com/browse/RPL-1633</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html">http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html">http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/server/doc/releasenotes_server.html">http://www.vmware.com/support/server/doc/releasenotes_server.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/player2/doc/releasenotes_player2.html">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/player/doc/releasenotes_player.html">http://www.vmware.com/support/player/doc/releasenotes_player.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html">http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html">http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html">http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html">http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/security/advisories/VMSA-2008-0005.html">http://www.vmware.com/security/advisories/VMSA-2008-0005.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.sybase.com/detail?id=1047991">http://www.sybase.com/detail?id=1047991</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.serv-u.com/releasenotes/">http://www.serv-u.com/releasenotes/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/28276">28276</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/22083">22083</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/489739/100/0/threaded">20080318 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/456546/100/200/threaded">20070110 VMware ESX server security updates</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0073.html">RHSA-2007:0073</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0072.html">RHSA-2007:0072</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0062.html">RHSA-2007:0062</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.029-bind.html">OpenPKG-SA-2006.029</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.018.html">OpenPKG-SA-2006.018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2007_10_ibmjava.html">SUSE-SA:2007:010</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_61_opera.html">SUSE-SA:2006:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_26_sr.html">SUSE-SR:2006:026</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:207">MDKSA-2006:207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:178">MDKSA-2006:178</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:177">MDKSA-2006:177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200610-06.xml">GLSA-200610-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0905/references">ADV-2008-0905</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/4224">ADV-2007-4224</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/2783">ADV-2007-2783</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/2315">ADV-2007-2315</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/2163">ADV-2007-2163</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1945">ADV-2007-1945</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1815">ADV-2007-1815</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1401">ADV-2007-1401</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/0343">ADV-2007-0343</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/0254">ADV-2007-0254</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/5146">ADV-2006-5146</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4750">ADV-2006-4750</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4744">ADV-2006-4744</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4586">ADV-2006-4586</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4417">ADV-2006-4417</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4366">ADV-2006-4366</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4329">ADV-2006-4329</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4327">ADV-2006-4327</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4216">ADV-2006-4216</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4207">ADV-2006-4207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4206">ADV-2006-4206</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4205">ADV-2006-4205</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3936">ADV-2006-3936</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3899">ADV-2006-3899</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtml">20061108 Multiple Vulnerabilities in OpenSSL library</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_response09186a008077af1b.html">20061108 Multiple Vulnerabilities in OpenSSL Library</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.bluecoat.com/support/knowledge/openSSL_RSA_Signature_forgery.html">http://www.bluecoat.com/support/knowledge/openSSL_RSA_Signature_forgery.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.arkoon.fr/upload/alertes/40AK-2006-04-FR-1.1_SSL360_OPENSSL_RSA.pdf">http://www.arkoon.fr/upload/alertes/40AK-2006-04-FR-1.1_SSL360_OPENSSL_RSA.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.attachmate.com/techdocs/2137.html">http://support.attachmate.com/techdocs/2137.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.attachmate.com/techdocs/2128.html">http://support.attachmate.com/techdocs/2128.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.attachmate.com/techdocs/2127.html">http://support.attachmate.com/techdocs/2127.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201534-1">201534</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201247-1">201247</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200708-1">200708</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102759-1">102759</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102744-1">102744</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102722-1">102722</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102696-1">102696</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102686-1">102686</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102657-1">102657</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102656-1">102656</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1">102648</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.566955">SSA:2006-310-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1017522">1017522</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28115">28115</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26893">26893</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26329">26329</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25649">25649</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25399">25399</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25284">25284</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24950">24950</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24930">24930</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24099">24099</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23915">23915</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23841">23841</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23794">23794</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23680">23680</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23455">23455</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23155">23155</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22949">22949</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22948">22948</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22940">22940</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22939">22939</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22938">22938</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22937">22937</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22936">22936</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22934">22934</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22932">22932</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22799">22799</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22758">22758</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22733">22733</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22711">22711</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22689">22689</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22671">22671</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22585">22585</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22545">22545</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22523">22523</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22513">22513</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22509">22509</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22446">22446</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22325">22325</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22284">22284</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22260">22260</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22232">22232</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22226">22226</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22066">22066</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22044">22044</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://openvpn.net/changelog.html">http://openvpn.net/changelog.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bind-announce&amp;m=116253119512445&amp;w=2">[bind-announce] 20061103 Internet Systems Consortium Security Advisory. [revised]</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.vmware.com/pipermail/security-announce/2008/000008.html">[security-announce] 20080317 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html">APPLE-SA-2007-12-14</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html">APPLE-SA-2006-11-28</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540">HPSBUX02186</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771">HPSBMA02250</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495">SSRT061273</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:207">MDKSA-2006:207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307177">http://docs.info.apple.com/article.html?artnum=307177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=304829">http://docs.info.apple.com/article.html?artnum=304829</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BEA</vuln:source>
            <vuln:reference xml:lang="en" href="http://dev2dev.bea.com/pub/advisory/238">BEA07-169.00</vuln:reference>
        </vuln:references>
        <vuln:summary>OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.</vuln:summary>
    </entry>
    <entry id="CVE-2007-0099">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:3.0" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
            <vuln:product>cpe:/a:microsoft:xml_core_services:3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-0099</vuln:cve-id>
        <vuln:published-datetime>2007-01-08T15:28:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-05T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-01-08T16:05:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:5793" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5793" />
        <vuln:cwe id="CWE-362" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA08-316A.html">TA08-316A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/21872">21872</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/Bulletin/MS08-069.mspx">MS08-069</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/3111">ADV-2008-3111</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/456343/100/0/threaded">20070104 Re: RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/455986/100/0/threaded">20070104 RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/455965/100/0/threaded">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1021164">1021164</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23655">23655</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://seclists.org/fulldisclosure/2007/Jan/0110.html">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/32627">32627</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://isc.sans.org/diary.php?storyid=2004">http://isc.sans.org/diary.php?storyid=2004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0113.html">20070104 Re: Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</vuln:reference>
        </vuln:references>
        <vuln:summary>Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."</vuln:summary>
    </entry>
    <entry id="CVE-2007-0243">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update16" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update1" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update10" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update11" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update12" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update2" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update4" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update5" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update6" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update7" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update8" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update9" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01a" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_16" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_18" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_03" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_08" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_09" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_10" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update18" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2_08</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2_09</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.3.1:update18</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2_03</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.3.1:update16</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update8</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update7</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update9</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update4</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update3</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update6</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.3.1_16</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update5</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.3.1_18</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update2</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update1</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update12</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update10</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update11</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.3.1_01a</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.3.1_01</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2_10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-0243</vuln:cve-id>
        <vuln:discovered-datetime>2006-06-16T00:00:00.000-04:00</vuln:discovered-datetime>
        <vuln:published-datetime>2007-01-17T17:28:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-02T01:21:54.047-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-01-18T09:13:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA07-022A.html">TA07-022A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/388289">VU#388289</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.zerodayinitiative.com/advisories/ZDI-07-005.html">http://www.zerodayinitiative.com/advisories/ZDI-07-005.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1">102760</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/31537">jre-gif-bo(31537)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/22085">22085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/457638/100/0/threaded">20070121 Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability Prove Of Concept Exploit</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/457159/100/0/threaded">20070117 ZDI-07-005: Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0956.html">RHSA-2007:0956</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0167.html">RHSA-2007:0167</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0166.html">RHSA-2007:0166</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2007_45_java.html">SUSE-SA:2007:045</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200702-07.xml">GLSA-200702-07</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/4224">ADV-2007-4224</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1814">ADV-2007-1814</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/0936">ADV-2007-0936</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/0211">ADV-2007-0211</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html">http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html">http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1017520">1017520</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/2158">2158</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200702-08.xml">GLSA-200702-08</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28115">28115</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27203">27203</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26645">26645</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26119">26119</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26049">26049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25283">25283</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24993">24993</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24468">24468</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24202">24202</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24189">24189</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23757">23757</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/32834">32834</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html">APPLE-SA-2007-12-14</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307177">http://docs.info.apple.com/article.html?artnum=307177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BEA</vuln:source>
            <vuln:reference xml:lang="en" href="http://dev2dev.bea.com/pub/advisory/242">BEA07-172.00</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.</vuln:summary>
    </entry>
    <entry id="CVE-2007-2872">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.2</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.7</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-2872</vuln:cve-id>
        <vuln:published-datetime>2007-06-04T13:30:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-01T01:33:05.217-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-06-05T08:38:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-189" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/releases/5_2_3.php">http://www.php.net/releases/5_2_3.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.html">FEDORA-2007-2215</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00354.html">FEDORA-2007-709</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://launchpad.net/bugs/173043">https://launchpad.net/bugs/173043</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-1702">https://issues.rpath.com/browse/RPL-1702</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-1693">https://issues.rpath.com/browse/RPL-1693</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39398">php-chunksplit-security-bypass(39398)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2008/0059">ADV-2008-0059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-549-1">USN-549-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-549-2">USN-549-2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2007/0023/">2007-0023</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1018186">1018186</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/24261">24261</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/470244/100/0/threaded">20070601 SEC Consult SA-20070601-0 :: PHP chunk_split() integer overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.sec-consult.com/291.html">http://www.sec-consult.com/291.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0891.html">RHSA-2007:0891</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0890.html">RHSA-2007:0890</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0888.html">RHSA-2007:0888</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/releases/4_4_8.php">http://www.php.net/releases/4_4_8.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/ChangeLog-4.php">http://www.php.net/ChangeLog-4.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.020.html">OpenPKG-SA-2007.020</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:187">MDKSA-2007:187</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml">GLSA-200710-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/3386">ADV-2007-3386</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/2061">ADV-2007-2061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm">http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.482863">SSA:2007-152-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28318">28318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27864">27864</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27545">27545</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27377">27377</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27351">27351</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27110">27110</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27102">27102</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27037">27037</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26967">26967</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26930">26930</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26895">26895</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26871">26871</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26838">26838</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26231">26231</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26048">26048</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25535">25535</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25456">25456</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2007-0889.html">RHSA-2007:0889</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html">SUSE-SA:2007:044</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501">HPSBUX02308</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/491693/100/0/threaded">SSRT080056</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0398">ADV-2008-0398</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.335136">SSA:2008-045-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30040">30040</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28936">28936</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28750">28750</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28658">28658</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html">SUSE-SA:2008:004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501">HPSBUX02308</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.</vuln:summary>
    </entry>
    <entry id="CVE-2007-3285">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:beta1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:rc2" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:rc3" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0:rc2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0:rc3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0:beta1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-3285</vuln:cve-id>
        <vuln:published-datetime>2007-06-20T15:30:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-26T01:02:24.127-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-06-21T10:26:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=383478">https://bugzilla.mozilla.org/show_bug.cgi?id=383478</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-490-1">USN-490-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1018413">1018413</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/24447">24447</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2007_49_mozilla.html">SUSE-SA:2007:049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2007/mfsa2007-22.html">http://www.mozilla.org/security/announce/2007/mfsa2007-22.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:152">MDKSA-2007:152</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.0x000000.com/?i=333">http://www.0x000000.com/?i=333</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html">http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26271">26271</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26258">26258</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26216">26216</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26204">26204</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26149">26149</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26072">26072</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/38032">38032</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">SSRT061181</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt">ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/4256">ADV-2007-4256</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1">201516</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1">103177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28135">28135</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">SSRT061181</vuln:reference>
        </vuln:references>
        <vuln:summary>Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.</vuln:summary>
    </entry>
    <entry id="CVE-2007-4465">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28:beta" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32:beta" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.34:beta" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.49" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.50" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.51" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.52" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.53" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.54" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.55" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.56" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.57" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.58" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.59" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.60" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.61" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.7" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.8" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:2.0.32:beta</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.55</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.56</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.57</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.58</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.59</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.50</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.51</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.52</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.53</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.54</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.6</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.9</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.8</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.7</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.49</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.34:beta</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28:beta</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.60</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.61</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-4465</vuln:cve-id>
        <vuln:published-datetime>2007-09-13T20:17:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T01:47:12.093-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-09-14T09:40:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:6089" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6089" />
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA08-150A.html">TA08-150A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/25653">25653</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/479237/100/0/threaded">20070912 Apache2 Undefined Charset UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.apache.org/dist/httpd/CHANGES_2.2.6">http://www.apache.org/dist/httpd/CHANGES_2.2.6</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3113">3113</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASONRES</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/achievement_securityalert/46">20070912 Apache2 Undefined Charset UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33105">33105</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31651">31651</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">HPSBUX02365</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">HPSBUX02365</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00353.html">FEDORA-2007-707</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/36586">apache-utf7-xss(36586)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-575-1">USN-575-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0008.html">RHSA-2008:0008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0006.html">RHSA-2008:0006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0005.html">RHSA-2008:0005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0004.html">RHSA-2008:0004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0911.html">RHSA-2007:0911</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html">FEDORA-2007-2214</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2007_61_apache2.html">SUSE-SA:2007:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:014">MDVSA-2008:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1697">ADV-2008-1697</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm">http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1019194">1019194</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200711-06.xml">GLSA-200711-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30430">30430</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28749">28749</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28607">28607</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28471">28471</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28467">28467</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27732">27732</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27563">27563</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26952">26952</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26842">26842</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html">APPLE-SA-2008-05-28</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.gentoo.org/show_bug.cgi?id=186219">http://bugs.gentoo.org/show_bug.cgi?id=186219</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset.  NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.</vuln:summary>
    </entry>
    <entry id="CVE-2007-6203">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.49" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.50" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.51" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.52" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.53" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.54" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.55" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.57" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.58" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.59" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.7" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.8" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:2.0.55</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.57</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.58</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.59</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.50</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.51</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.52</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.53</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.54</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.6</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.8</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.7</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.49</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-6203</vuln:cve-id>
        <vuln:published-datetime>2007-12-03T17:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T01:52:50.377-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-12-04T11:13:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/38800">apache-413error-xss(38800)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/USN-731-1">USN-731-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019030">1019030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/26663">26663</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/484410/100/0/threaded">20071130 PR07-37: XSS on Apache HTTP Server 413 error pages via malformed HTTP method</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1875/references">ADV-2008-1875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/4301">ADV-2007-4301</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/4060">ADV-2007-4060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg1PK57952">PK57952</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34219">34219</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33105">33105</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30732">30732</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28196">28196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27906">27906</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://procheckup.com/Vulnerability_PR07-37.php">http://procheckup.com/Vulnerability_PR07-37.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1623/references">ADV-2008-1623</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg24019245">PK65782</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3411">3411</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200803-19.xml">GLSA-200803-19</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30356">30356</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29640">29640</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29420">29420</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29348">29348</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html">SUSE-SA:2008:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
        </vuln:references>
        <vuln:summary>Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0005">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0005</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T01:54:30.797-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T09:37:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html">FEDORA-2008-1695</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html">FEDORA-2008-1711</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39615">apache-modproxyftp-utf7-xss(39615)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-575-1">USN-575-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019185">1019185</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27234">27234</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/505990/100/0/threaded">20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486167/100/0/threaded">20080110 SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0009.html">RHSA-2008:0009</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0008.html">RHSA-2008:0008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0007.html">RHSA-2008:0007</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0006.html">RHSA-2008:0006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0005.html">RHSA-2008:0005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0004.html">RHSA-2008:0004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:016">MDVSA-2008:016</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:015">MDVSA-2008:015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:014">MDVSA-2008:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1875/references">ADV-2008-1875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm">http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3526">3526</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASONRES</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/achievement_securityalert/49">20080110 Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200803-19.xml">GLSA-200803-19</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30732">30732</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29640">29640</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29420">29420</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29348">29348</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28977">28977</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28749">28749</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28607">28607</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28526">28526</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28471">28471</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28467">28467</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.vmware.com/pipermail/security-announce/2009/000062.html">[security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html">SUSE-SA:2008:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
        </vuln:references>
        <vuln:summary>mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0599">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:5.0.0:rc3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0:rc2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0:rc1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0:beta2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0:beta1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0:beta4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0:beta3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0599</vuln:cve-id>
        <vuln:published-datetime>2008-05-05T13:20:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T01:56:17.733-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-05-06T10:01:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:5510" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5510" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/147027">VU#147027</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00779.html">FEDORA-2008-3606</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00773.html">FEDORA-2008-3864</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-2503">https://issues.rpath.com/browse/RPL-2503</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/42137">php-vector-unspecified(42137)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-628-1">USN-628-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019958">1019958</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/29009">29009</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/492535/100/0/threaded">20080523 rPSA-2008-0176-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0505.html">RHSA-2008:0505</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/ChangeLog-5.php">http://www.php.net/ChangeLog-5.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2008/05/02/2">[oss-security] 20080502 CVE Request (PHP)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:128">MDVSA-2008:128</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:127">MDVSA-2008:127</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/2268">ADV-2008-2268</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1810/references">ADV-2008-1810</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1412">ADV-2008-1412</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0176">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0176</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31326">31326</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31200">31200</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30828">30828</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30757">30757</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30616">30616</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30345">30345</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30083">30083</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30048">30048</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=slackware-security&amp;m=121022465827871&amp;w=2">SSA:2008-128-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html">APPLE-SA-2008-07-31</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01476437">SSRT080063</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01476437">SSRT080063</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://cvs.php.net/viewvc.cgi/php-src/sapi/cgi/cgi_main.c?r1=1.267.2.15.2.50.2.12&amp;r2=1.267.2.15.2.50.2.13&amp;diff_format=u">http://cvs.php.net/viewvc.cgi/php-src/sapi/cgi/cgi_main.c?r1=1.267.2.15.2.50.2.12&amp;r2=1.267.2.15.2.50.2.13&amp;diff_format=u</vuln:reference>
        </vuln:references>
        <vuln:summary>The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.</vuln:summary>
    </entry>
    <entry id="CVE-2008-2168">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28:beta" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32:beta" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.34:beta" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.49" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.50" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.51" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.52" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.53" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.54" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.55" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.56" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.57" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.58" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.59" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.60" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.61" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.7" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.8" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:2.0.32:beta</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.55</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.56</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.57</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.58</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.59</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.50</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.51</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.52</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.53</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.54</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.6</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.9</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.8</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.7</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.49</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.34:beta</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28:beta</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.60</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.61</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-2168</vuln:cve-id>
        <vuln:published-datetime>2008-05-13T17:20:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:01:05.907-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-05-13T20:26:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:5143" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5143" />
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/42303">apache-403-xss(42303)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/USN-731-1">USN-731-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/29112">29112</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/491967/100/0/threaded">20080512 Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/491930/100/0/threaded">20080510 Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/491901/100/0/threaded">20080510 Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/491862/100/0/threaded">20080508 Apache Server HTML Injection and UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3889">3889</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34219">34219</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31651">31651</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">SSRT080118</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">SSRT080118</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.</vuln:summary>
    </entry>
    <entry id="CVE-2008-2364">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache_http_server:2.0.63" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache_http_server:2.2.8" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache_software_foundation:apache_http_server:2.2.8</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache_http_server:2.0.63</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-2364</vuln:cve-id>
        <vuln:published-datetime>2008-06-13T14:41:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:01:38.453-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-06-16T09:42:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:6084" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6084" />
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/29653">29653</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1798">ADV-2008-1798</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00153.html">FEDORA-2008-6314</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00055.html">FEDORA-2008-6393</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/42987">apache-modproxy-module-dos(42987)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/USN-731-1">USN-731-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1020267">1020267</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/31681">31681</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/498567/100/0/threaded">20081122 rPSA-2008-0328-1 httpd mod_ssl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/494858/100/0/threaded">20080729 rPSA-2008-0236-1 httpd mod_ssl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0966.html">RHSA-2008:0966</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:237">MDVSA-2008:237</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:195">MDVSA-2008:195</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0320">ADV-2009-0320</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/2780">ADV-2008-2780</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg1PK67579">PK67579</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-01.ibm.com/support/docview.wss?uid=swg27008517">http://www-01.ibm.com/support/docview.wss?uid=swg27008517</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=666154&amp;r2=666153&amp;pathrev=666154">http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=666154&amp;r2=666153&amp;pathrev=666154</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3216">http://support.apple.com/kb/HT3216</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1">247666</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200807-06.xml">GLSA-200807-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34418">34418</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34259">34259</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34219">34219</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33797">33797</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33156">33156</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32838">32838</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32685">32685</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32222">32222</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31904">31904</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31651">31651</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31416">31416</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31404">31404</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31026">31026</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30621">30621</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2008-0967.html">RHSA-2008:0967</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=123376588623823&amp;w=2">SSRT090005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=123376588623823&amp;w=2">SSRT090005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html">SUSE-SR:2009:007</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html">SUSE-SR:2009:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html">APPLE-SA-2008-10-09</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">HPSBUX02365</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">HPSBUX02365</vuln:reference>
        </vuln:references>
        <vuln:summary>The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.</vuln:summary>
    </entry>
    <entry id="CVE-2008-2666">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.6</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0:rc2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0:rc3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0:rc1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-2666</vuln:cve-id>
        <vuln:published-datetime>2008-06-19T21:41:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:02:17.547-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-06-20T10:24:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/43198">php-chdir-ftoc-security-bypass(43198)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1020328">1020328</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/29796">29796</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3942">3942</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASONRES</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/achievement_securityalert/55">20080617 PHP 5.2.6 chdir(),ftok() (standard ext) safe_mode bypass</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35074">35074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a subdirectory named http: and then placing ../ (dot dot slash) sequences in an http URL argument to the (1) chdir or (2) ftok function.</vuln:summary>
    </entry>
    <entry id="CVE-2008-2665">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:5.2.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-2665</vuln:cve-id>
        <vuln:published-datetime>2008-06-19T21:41:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:02:17.420-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-06-20T10:12:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-22" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/43196">php-posixaccess-security-bypass(43196)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1020327">1020327</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/29797">29797</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3941">3941</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASONRES</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/achievement_securityalert/54">20080617 PHP 5.2.6 posix_access() (posix ext) safe_mode bypass</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35074">35074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</vuln:reference>
        </vuln:references>
        <vuln:summary>Directory traversal vulnerability in the posix_access function in PHP 5.2.6 and earlier allows remote attackers to bypass safe_mode restrictions via a .. (dot dot) in an http URL, which results in the URL being canonicalized to a local filename after the safe_mode check has successfully run.</vuln:summary>
    </entry>
    <entry id="CVE-2008-2829">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:5.2.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.6</vuln:product>
            <vuln:product>cpe:/a:php:php:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-2829</vuln:cve-id>
        <vuln:published-datetime>2008-06-23T16:41:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:03:01.827-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-06-23T17:29:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/29829">29829</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html">FEDORA-2009-3848</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html">FEDORA-2009-3768</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugs.gentoo.org/show_bug.cgi?id=221969">https://bugs.gentoo.org/show_bug.cgi?id=221969</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/43357">php-phpimap-dos(43357)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-628-1">USN-628-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2008/06/24/2">[oss-security] 20080624 Re: CVE request: php 5.2.6 ext/imap buffer overflows</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2008/06/19/6">[oss-security] 20080619 CVE request: php 5.2.6 ext/imap buffer overflows</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:128">MDVSA-2008:128</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:127">MDVSA-2008:127</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:126">MDVSA-2008:126</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35306">35306</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35074">35074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31200">31200</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/46641">46641</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html">SUSE-SR:2008:027</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.php.net/bug.php?id=42862">http://bugs.php.net/bug.php?id=42862</vuln:reference>
        </vuln:references>
        <vuln:summary>php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.</vuln:summary>
    </entry>
    <entry id="CVE-2008-2371">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:pcre:pcre:7.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:pcre:pcre:7.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-2371</vuln:cve-id>
        <vuln:published-datetime>2008-07-07T19:41:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:01:39.203-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-07-08T10:43:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00123.html">FEDORA-2008-6048</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00105.html">FEDORA-2008-6025</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2008/2336">ADV-2008-2336</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-628-1">USN-628-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-624-1">USN-624-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/31681">31681</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/30087">30087</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/497828/100/0/threaded">20081027 rPSA-2008-0305-1 pcre</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:023">MDVSA-2009:023</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:147">MDVSA-2008:147</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200807-03.xml">GLSA-200807-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/2780">ADV-2008-2780</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/2006">ADV-2008-2006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/2005">ADV-2008-2005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1602">DSA-1602</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0305">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0305</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3216">http://support.apple.com/kb/HT3216</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35074">35074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32454">32454</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32222">32222</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31200">31200</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30990">30990</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30972">30972</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30967">30967</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30961">30961</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30958">30958</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30945">30945</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30944">30944</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30916">30916</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html">SUSE-SR:2008:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html">APPLE-SA-2008-10-09</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://ftp.gnome.org/pub/GNOME/sources/glib/2.16/glib-2.16.4.changes">http://ftp.gnome.org/pub/GNOME/sources/glib/2.16/glib-2.16.4.changes</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.gentoo.org/show_bug.cgi?id=228091">http://bugs.gentoo.org/show_bug.cgi?id=228091</vuln:reference>
        </vuln:references>
        <vuln:summary>Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.</vuln:summary>
    </entry>
    <entry id="CVE-2008-2939">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.49" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.50" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.51" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.52" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.53" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.54" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.55" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.57" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.58" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.59" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.12" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.13" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.14" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.15" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.16" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.17" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.18" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.19" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.20" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.21" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.22" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.23" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.24" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.25" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.26" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.27" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.29" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.30" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.31" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.33" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.34" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.61" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0:a1" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0:a2" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0:a3" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0:a4" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0:a5" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0:a6" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0:a7" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0:a8" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0:a9" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.2.8" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.0.63" />
                <cpe-lang:fact-ref name="cpe:/a:apache_software_foundation:apache:2.2.9" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.2.6</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.2.8</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.2.9</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.55</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.57</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.58</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.59</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.50</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.51</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.52</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.53</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.54</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.3</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.13</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.14</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.11</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.12</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.17</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.18</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.15</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.16</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.49</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0:a2</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0:a1</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.19</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0:a6</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0:a5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0:a4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0:a3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.26</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.27</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.29</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.22</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.23</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.24</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.25</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.20</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.21</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0:a8</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0:a7</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0:a9</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.63</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.61</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.33</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.34</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.31</vuln:product>
            <vuln:product>cpe:/a:apache_software_foundation:apache:2.0.30</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-2939</vuln:cve-id>
        <vuln:published-datetime>2008-08-06T14:41:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:03:29.500-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-08-07T09:35:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/663763">VU#663763</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/44223">apache-modproxyftp-xss(44223)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/USN-731-1">USN-731-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1020635">1020635</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/30560">30560</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/498567/100/0/threaded">20081122 rPSA-2008-0328-1 httpd mod_ssl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/498566/100/0/threaded">20081122 rPSA-2008-0327-1 httpd mod_ssl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/495180/100/0/threaded">20080806 Apache HTTP Server mod_proxy_ftp Wildcard Characters Cross-Site Scripting</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0966.html">RHSA-2008:0966</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.rapid7.com/advisories/R7-0033">http://www.rapid7.com/advisories/R7-0033</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:124">MDVSA-2009:124</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:195">MDVSA-2008:195</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:194">MDVSA-2008:194</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0320">ADV-2009-0320</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/2461">ADV-2008-2461</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/2315">ADV-2008-2315</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg1PK70937">PK70937</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg1PK70197">PK70197</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/Advisories:rPSA-2008-0327">http://wiki.rpath.com/Advisories:rPSA-2008-0327</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://svn.apache.org/viewvc?view=rev&amp;revision=682871">http://svn.apache.org/viewvc?view=rev&amp;revision=682871</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://svn.apache.org/viewvc?view=rev&amp;revision=682870">http://svn.apache.org/viewvc?view=rev&amp;revision=682870</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://svn.apache.org/viewvc?view=rev&amp;revision=682868">http://svn.apache.org/viewvc?view=rev&amp;revision=682868</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1">247666</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35074">35074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34219">34219</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33797">33797</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33156">33156</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32838">32838</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32685">32685</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31673">31673</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31384">31384</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2008-0967.html">RHSA-2008:0967</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=123376588623823&amp;w=2">SSRT090005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=123376588623823&amp;w=2">SSRT090005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.html">SUSE-SR:2008:024</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.</vuln:summary>
    </entry>
    <entry id="CVE-2008-3660">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.6" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.7" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.8" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.6</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.5</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.8</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.7</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-3660</vuln:cve-id>
        <vuln:published-datetime>2008-08-14T20:41:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:05:32.233-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-08-15T13:34:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-20" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html">FEDORA-2009-3848</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html">FEDORA-2009-3768</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/44402">php-curl-unspecified(44402)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2008/2336">ADV-2008-2336</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1020994">1020994</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-0350.html">RHSA-2009:0350</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2008/08/13/8">[oss-security] 20080813 Re: CVE request: php-5.2.6 overflow issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2008/08/08/2">[oss-security] 20080808 CVE request: php-5.2.6 overflow issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:024">MDVSA-2009:024</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:023">MDVSA-2009:023</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:022">MDVSA-2009:022</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:021">MDVSA-2009:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1647">DSA-1647</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35306">35306</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35074">35074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32148">32148</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31982">31982</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html">SUSE-SR:2008:018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.gentoo.org/show_bug.cgi?id=234102">http://bugs.gentoo.org/show_bug.cgi?id=234102</vuln:reference>
        </vuln:references>
        <vuln:summary>PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.</vuln:summary>
    </entry>
    <entry id="CVE-2008-3659">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.6" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.7" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.8" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.6</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.5</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.8</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.7</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-3659</vuln:cve-id>
        <vuln:published-datetime>2008-08-14T20:41:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:05:32.110-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.4</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-08-15T13:07:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/archive/2008.php#id2008-08-07-1">http://www.php.net/archive/2008.php#id2008-08-07-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/44405">php-memnstr-bo(44405)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2008/2336">ADV-2008-2336</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1020995">1020995</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2008/08/13/8">[oss-security] 20080813 Re: CVE request: php-5.2.6 overflow issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2008/08/08/4">[oss-security] 20080808 Re: CVE request: php-5.2.6 overflow issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2008/08/08/3">[oss-security] 20080808 Re: CVE request: php-5.2.6 overflow issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2008/08/08/2">[oss-security] 20080808 CVE request: php-5.2.6 overflow issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:024">MDVSA-2009:024</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:023">MDVSA-2009:023</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:022">MDVSA-2009:022</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:021">MDVSA-2009:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1647">DSA-1647</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35074">35074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32316">32316</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32148">32148</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31982">31982</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/47483">47483</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://news.php.net/php.cvs/52002">http://news.php.net/php.cvs/52002</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.html">SUSE-SR:2008:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html">SUSE-SR:2008:018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.gentoo.org/show_bug.cgi?id=234102">http://bugs.gentoo.org/show_bug.cgi?id=234102</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the memnstr function in PHP 4.4.x before 4.4.9 and PHP 5.6 through 5.2.6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via the delimiter argument to the explode function.  NOTE: the scope of this issue is limited since most applications would not use an attacker-controlled delimiter, but local attacks against safe_mode are feasible.</vuln:summary>
    </entry>
    <entry id="CVE-2008-3658">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.6" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.7" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.8" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.6" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.6</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.5</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.8</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.7</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.6</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-3658</vuln:cve-id>
        <vuln:published-datetime>2008-08-14T20:41:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T02:05:31.983-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-08-15T12:51:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html">FEDORA-2009-3848</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html">FEDORA-2009-3768</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/44401">php-imageloadfont-dos(44401)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2008/2336">ADV-2008-2336</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/30649">30649</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/498647/100/0/threaded">HPSBTU02382</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/498647/100/0/threaded">HPSBTU02382</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-0350.html">RHSA-2009:0350</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/archive/2008.php#id2008-08-07-1">http://www.php.net/archive/2008.php#id2008-08-07-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2008/08/13/8">[oss-security] 20080813 Re: CVE request: php-5.2.6 overflow issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2008/08/08/2">[oss-security] 20080808 CVE request: php-5.2.6 overflow issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:024">MDVSA-2009:024</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:023">MDVSA-2009:023</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:022">MDVSA-2009:022</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:021">MDVSA-2009:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2009/0320">ADV-2009-0320</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/3275">ADV-2008-3275</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1647">DSA-1647</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35306">35306</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35074">35074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33797">33797</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32884">32884</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32316">32316</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32148">32148</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31982">31982</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/47484">47484</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://news.php.net/php.cvs/51219">http://news.php.net/php.cvs/51219</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=123376588623823&amp;w=2">HPSBUX02401</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=123376588623823&amp;w=2">HPSBUX02401</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.html">SUSE-SR:2008:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html">SUSE-SR:2008:018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.gentoo.org/show_bug.cgi?id=234102">http://bugs.gentoo.org/show_bug.cgi?id=234102</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the imageloadfont function in ext/gd/gd.c in PHP 4.4.x before 4.4.9 and PHP 5.2 before 5.2.6-r6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.</vuln:summary>
    </entry>
    <entry id="CVE-2008-5029">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.20.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.19.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23_rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24_rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24_rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.16" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22_rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22_rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.21.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.23.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24_rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.4.36.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.2.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.12::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.11::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.8::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.7::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.6::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.5::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.4::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.3::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.2::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.10::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.1::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.18:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.22" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.21" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.19" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.24.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.17" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.18" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.22.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25.9::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.25::x86_64" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.26:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.27.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.8::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22_rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22_rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.20.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.8</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.9</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.10::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.7::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.16</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.9::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23_rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.21.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.6::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.11::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.19</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.17</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.14</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.15</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.12</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.13</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.18</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.10</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.11</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24_rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24_rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.4::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.3::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24_rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.4.36</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.26</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.20</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.21</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.12::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.2::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.1::x86_64</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.22</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.2.27</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.23</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.24.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.6</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.19.7</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.27.4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.25.5::x86_64</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-5029</vuln:cve-id>
        <vuln:published-datetime>2008-11-10T11:15:12.060-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-06T01:46:41.687-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.9</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-11-11T11:21:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/32154">32154</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="https://rhn.redhat.com/errata/RHSA-2009-1550.html">RHSA-2009:1550</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=470201">https://bugzilla.redhat.com/show_bug.cgi?id=470201</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-679-1">USN-679-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021511">1021511</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021292">1021292</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/33079">33079</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/499700/100/0/threaded">20090101 Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-0225.html">RHSA-2009:0225</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-0014.html">RHSA-2009:0014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-0009.html">RHSA-2009:0009</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2008/11/06/1">[oss-security] 20081106 CVE request: kernel: Unix sockets kernel panic</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:234">MDVSA-2008:234</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1687">DSA-1687</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1681">DSA-1681</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4573">4573</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33704">33704</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33641">33641</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33623">33623</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33586">33586</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33556">33556</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33180">33180</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32998">32998</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32918">32918</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=linux-netdev&amp;m=122593044330973&amp;w=2">[linux-netdev] 20081106 UNIX sockets kernel panic</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html">SUSE-SA:2009:008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html">SUSE-SA:2009:004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html">SUSE-SA:2008:057</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://darkircop.org/unix.c">http://darkircop.org/unix.c</vuln:reference>
        </vuln:references>
        <vuln:summary>The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.</vuln:summary>
    </entry>
    <entry id="CVE-2008-5300">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:kernel:2.6.28:rc5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:kernel:2.6.28</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-5300</vuln:cve-id>
        <vuln:published-datetime>2008-12-01T12:30:00.203-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-06T01:47:08.127-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.9</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-12-02T14:14:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01358.html">FEDORA-2008-11618</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="https://rhn.redhat.com/errata/RHSA-2009-1550.html">RHSA-2009:1550</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-2915">https://issues.rpath.com/browse/RPL-2915</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=470201">https://bugzilla.redhat.com/show_bug.cgi?id=470201</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/46943">linux-kernel-sendmsg-dos(46943)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-714-1">USN-714-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-715-1">USN-715-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/32516">32516</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/499044/100/0/threaded">20081209 rPSA-2008-0332-1 kernel</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-0053.html">RHSA-2009:0053</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-0014.html">RHSA-2009:0014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:032">MDVSA-2009:032</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1681">DSA-1681</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0332">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0332</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/4673">4673</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33854">33854</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33756">33756</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33706">33706</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33556">33556</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33348">33348</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33083">33083</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32998">32998</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32913">32913</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/50272">50272</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=linux-netdev&amp;m=122765505415944&amp;w=2">[linux-netdev] 20081125 [PATCH] Fix soft lockups/OOM issues w/ unix garbage collector</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=linux-netdev&amp;m=122721862313564&amp;w=2">[linux-netdev] 20081120 soft lockups/OOM after unix socket fixes</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=473259">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=473259</vuln:reference>
        </vuln:references>
        <vuln:summary>Linux kernel 2.6.28 allows local users to cause a denial of service ("soft lockup" and process loss) via a large number of sendmsg function calls, which does not block during AF_UNIX garbage collection and triggers an OOM condition, a different vulnerability than CVE-2008-5029.</vuln:summary>
    </entry>
    <entry id="CVE-2008-5349">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:6:update_5" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:6:update_8" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:6" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:6:update_2" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:6:update_1" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:6:update_7" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:6:update_4" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:6:update_6" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:6:update_3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:6" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:6:update_7" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:6:update_1" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:6:update_3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:6:update_2" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:6:update_5" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:6:update_4" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:6:update_8" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:6:update_6" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:6:update_10" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:6:update_10" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:5.0:update_1" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:5.0:update_2" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:5.0:update_3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:5.0:update_10" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:5.0:update_11" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:5.0:update_12" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:5.0:update_13" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:5.0:update_14" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:5.0:update_15" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:5.0:update_16" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:5.0:update_12" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:5.0:update_13" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:5.0:update_10" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:5.0:update_11" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:5.0:update_2" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:5.0:update_1" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:5.0:update_15" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:5.0:update_14" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:5.0:update_16" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sun:jre:6:update_10</vuln:product>
            <vuln:product>cpe:/a:sun:jre:6:update_8</vuln:product>
            <vuln:product>cpe:/a:sun:jre:6:update_7</vuln:product>
            <vuln:product>cpe:/a:sun:jre:6:update_6</vuln:product>
            <vuln:product>cpe:/a:sun:jre:6:update_5</vuln:product>
            <vuln:product>cpe:/a:sun:jre:6:update_4</vuln:product>
            <vuln:product>cpe:/a:sun:jre:6:update_3</vuln:product>
            <vuln:product>cpe:/a:sun:jre:6:update_2</vuln:product>
            <vuln:product>cpe:/a:sun:jre:6:update_1</vuln:product>
            <vuln:product>cpe:/a:sun:jre:5.0:update_16</vuln:product>
            <vuln:product>cpe:/a:sun:jre:5.0:update_15</vuln:product>
            <vuln:product>cpe:/a:sun:jre:5.0:update_14</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:6:update_2</vuln:product>
            <vuln:product>cpe:/a:sun:jre:5.0:update_13</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:6:update_1</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:5.0:update_1</vuln:product>
            <vuln:product>cpe:/a:sun:jre:5.0:update_12</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:6:update_4</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:5.0:update_2</vuln:product>
            <vuln:product>cpe:/a:sun:jre:5.0:update_11</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:6:update_3</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:6:update_10</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:5.0:update_3</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:6:update_6</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:6</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:6:update_5</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:6:update_8</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:6:update_7</vuln:product>
            <vuln:product>cpe:/a:sun:jre:5.0:update_2</vuln:product>
            <vuln:product>cpe:/a:sun:jre:5.0:update_1</vuln:product>
            <vuln:product>cpe:/a:sun:jre:6</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:5.0:update_16</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:5.0:update_15</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:5.0:update_12</vuln:product>
            <vuln:product>cpe:/a:sun:jre:5.0:update_10</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:5.0:update_11</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:5.0:update_14</vuln:product>
            <vuln:product>cpe:/a:sun:jre:5.0</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:5.0:update_13</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:5.0:update_10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-5349</vuln:cve-id>
        <vuln:published-datetime>2008-12-05T06:30:00.457-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T01:19:15.000-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.1</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-12-05T13:44:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA08-340A.html">TA08-340A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-246286-1">246286</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="https://rhn.redhat.com/errata/RHSA-2009-0466.html">RHSA-2009:0466</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdf">http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/1426">ADV-2009-1426</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1021309">1021309</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/32608">32608</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/504010/100/0/threaded">HPSBUX02429</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-0016.html">RHSA-2009:0016</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/3339">ADV-2008-3339</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=829914&amp;poid=">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=829914&amp;poid=</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2009-012.htm">http://support.avaya.com/elmodocs2/security/ASA-2009-012.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35255">35255</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34972">34972</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34259">34259</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33709">33709</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33015">33015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/32991">32991</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2008-1025.html">RHSA-2008:1025</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2008-1018.html">RHSA-2008:1018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/50504">50504</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="