<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" nvd_xml_version="2.0" pub_date="2013-05-23T05:01:36" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
  <entry id="CVE-2007-6746">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:canonical:telepathy-idle:0.1.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:canonical:telepathy-idle:0.1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:canonical:telepathy-idle:0.1.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:canonical:telepathy-idle:0.1.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:canonical:telepathy-idle:0.1.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:canonical:telepathy-idle:0.1.10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:13.04"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:12.04:-:lts"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:canonical:telepathy-idle:0.1.14</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:13.04</vuln:product>
      <vuln:product>cpe:/a:canonical:telepathy-idle:0.1.14.1</vuln:product>
      <vuln:product>cpe:/a:canonical:telepathy-idle:0.1.11.2</vuln:product>
      <vuln:product>cpe:/a:canonical:telepathy-idle:0.1.11.1</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.04:-:lts</vuln:product>
      <vuln:product>cpe:/a:canonical:telepathy-idle:0.1.12.1</vuln:product>
      <vuln:product>cpe:/a:canonical:telepathy-idle:0.1.10.1</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:12.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-6746</vuln:cve-id>
    <vuln:published-datetime>2013-05-21T14:55:01.310-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T08:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.freedesktop.org/show_bug.cgi?id=63810" xml:lang="en">https://bugs.freedesktop.org/show_bug.cgi?id=63810</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-1821-1" xml:lang="en">USN-1821-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/59474" xml:lang="en">59474</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/04/24/5" xml:lang="en">[oss-security] 20130424 CVE(-2007-xxxx?) request: telepathy-idle does not check SSL certificates</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/53361" xml:lang="en">53361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2013-May/104397.html" xml:lang="en">FEDORA-2013-6534</vuln:reference>
    </vuln:references>
    <vuln:summary>telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</vuln:summary>
  </entry>
  <entry id="CVE-2009-4355">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8l"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8k"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8j"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8g"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8f"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7f"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7g"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.7a-2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7j"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7k"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7l"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7m"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.6b-3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g"/>
        <cpe-lang:fact-ref name="cpe:/a:redhat:openssl:0.9.6-15"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6f"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6i"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6k"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6j"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6m"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6l"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.2b"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.1c"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:1.0.0:beta4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6:beta2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta1</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.6b-3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7k</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.2b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8f</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8k</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7h</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a:beta2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5a:beta2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.7a-2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6:beta3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.1c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7f</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8e</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8l</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6l</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5a:beta1</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6f</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8j</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6j</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6a:beta3</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta5</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8i</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.3a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5:beta2</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.5a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta6</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7g</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6k</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7a</vuln:product>
      <vuln:product>cpe:/a:redhat:openssl:0.9.6-15</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8a</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:1.0.0:beta4</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8b</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7l</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.6m</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7j</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7m</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8g</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.8d</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl:0.9.7:beta2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2009-4355</vuln:cve-id>
    <vuln:published-datetime>2010-01-14T14:30:00.390-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-21T14:56:17.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-01-15T10:14:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:6678" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6678" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:12168" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12168" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:assessment_check name="oval:org.mitre.oval:def:11260" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11260" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2010-0095.html" xml:lang="en">RHSA-2010:0095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://kb.bluecoat.com/index?page=content&amp;id=SA50" xml:lang="en">https://kb.bluecoat.com/index?page=content&amp;id=SA50</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-3157" xml:lang="en">https://issues.rpath.com/browse/RPL-3157</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=546707" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=546707</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0916" xml:lang="en">ADV-2010-0916</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0839" xml:lang="en">ADV-2010-0839</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/0124" xml:lang="en">ADV-2010-0124</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/USN-884-1" xml:lang="en">USN-884-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2010/01/13/3" xml:lang="en">[oss-security] 20100113 [PATCH] memory consumption (DoS) in openssl CVE-2009-4355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2010:022" xml:lang="en">MDVSA-2010:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2010/dsa-1970" xml:lang="en">DSA-1970</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0004" xml:lang="en">http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2010&amp;m=slackware-security.663049" xml:lang="en">SSA:2010-060-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42733" xml:lang="en">42733</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42724" xml:lang="en">42724</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/39461" xml:lang="en">39461</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38761" xml:lang="en">38761</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38200" xml:lang="en">38200</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38181" xml:lang="en">38181</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/38175" xml:lang="en">38175</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html" xml:lang="en">SUSE-SA:2010:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html" xml:lang="en">FEDORA-2010-5357</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.html" xml:lang="en">FEDORA-2010-5744</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.openssl.org/chngview?cn=19167" xml:lang="en">http://cvs.openssl.org/chngview?cn=19167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.openssl.org/chngview?cn=19069" xml:lang="en">http://cvs.openssl.org/chngview?cn=19069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.openssl.org/chngview?cn=19068" xml:lang="en">http://cvs.openssl.org/chngview?cn=19068</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6678" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6678" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:11260" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:11260" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:12168" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:12168" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.</vuln:summary>
  </entry>
  <entry id="CVE-2010-2772">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:siemens:simatic_wincc:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:siemens:simatic_wincc:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:siemens:simatic_wincc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:siemens:simatic_pcs_7:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:siemens:simatic_pcs_7:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:siemens:simatic_pcs_7:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:siemens:simatic_pcs_7:7.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:siemens:simatic_pcs_7:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:siemens:simatic_pcs_7:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:siemens:simatic_pcs_7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:siemens:simatic_pcs_7:7.1</vuln:product>
      <vuln:product>cpe:/a:siemens:simatic_pcs_7:7.0</vuln:product>
      <vuln:product>cpe:/a:siemens:simatic_pcs_7</vuln:product>
      <vuln:product>cpe:/a:siemens:simatic_pcs_7:7.1:sp1</vuln:product>
      <vuln:product>cpe:/a:siemens:simatic_wincc</vuln:product>
      <vuln:product>cpe:/a:siemens:simatic_pcs_7:6.1</vuln:product>
      <vuln:product>cpe:/a:siemens:simatic_wincc:6.2</vuln:product>
      <vuln:product>cpe:/a:siemens:simatic_pcs_7:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:siemens:simatic_pcs_7:6.0</vuln:product>
      <vuln:product>cpe:/a:siemens:simatic_wincc:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2010-2772</vuln:cve-id>
    <vuln:published-datetime>2010-07-22T01:43:58.250-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T22:57:42.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2010-07-22T14:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/60587" xml:lang="en">simatic-wincc-default-password(60587)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.wired.com/threatlevel/2010/07/siemens-scada/" xml:lang="en">http://www.wired.com/threatlevel/2010/07/siemens-scada/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.wilderssecurity.com/showpost.php?p=1712134&amp;postcount=22" xml:lang="en">http://www.wilderssecurity.com/showpost.php?p=1712134&amp;postcount=22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2010/1893" xml:lang="en">ADV-2010-1893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/41753" xml:lang="en">41753</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sea.siemens.com/us/News/Industrial/Pages/WinCC_Update.aspx" xml:lang="en">http://www.sea.siemens.com/us/News/Industrial/Pages/WinCC_Update.aspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.f-secure.com/weblog/archives/00001987.html" xml:lang="en">http://www.f-secure.com/weblog/archives/00001987.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.automation.siemens.com/forum/guests/PostShow.aspx?PostID=16127&amp;16127&amp;Language=en&amp;PageIndex=1" xml:lang="en">http://www.automation.siemens.com/forum/guests/PostShow.aspx?PostID=16127&amp;16127&amp;Language=en&amp;PageIndex=1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.automation.siemens.com/WW/llisapi.dll?func=cslib.csinfo&amp;lang=en&amp;objid=43876783&amp;caller=viewhttp://support.automation.siemens.com/WW/llisapi.dll?func=cslib.csinfo&amp;lang=en&amp;objid=43876783&amp;c" xml:lang="en">http://support.automation.siemens.com/WW/llisapi.dll?func=cslib.csinfo&amp;lang=en&amp;objid=43876783&amp;caller=viewhttp://support.automation.siemens.com/WW/llisapi.dll?func=cslib.csinfo&amp;lang=en&amp;objid=43876783&amp;c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/40682" xml:lang="en">40682</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/" xml:lang="en">http://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://infoworld.com/d/security-central/siemens-warns-users-dont-change-passwords-after-worm-attack-915?sourcefssr" xml:lang="en">http://infoworld.com/d/security-central/siemens-warns-users-dont-change-passwords-after-worm-attack-915?sourcefssr</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://infoworld.com/d/security-central/new-weaponized-virus-targets-industrial-secrets-725" xml:lang="en">http://infoworld.com/d/security-central/new-weaponized-virus-targets-industrial-secrets-725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-205-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-205-01</vuln:reference>
    </vuln:references>
    <vuln:summary>Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0340">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:indusoft:web_studio:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:indusoft:web_studio:6.1:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:indusoft:thin_client:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:advantech:advantech_studio:6.1:sp6_61.6.01.05"/>
        <cpe-lang:fact-ref name="cpe:/a:indusoft:web_studio:6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:indusoft:web_studio:6.1:sp6</vuln:product>
      <vuln:product>cpe:/a:indusoft:web_studio:7.0</vuln:product>
      <vuln:product>cpe:/a:advantech:advantech_studio:6.1:sp6_61.6.01.05</vuln:product>
      <vuln:product>cpe:/a:indusoft:web_studio:6.1</vuln:product>
      <vuln:product>cpe:/a:indusoft:thin_client:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0340</vuln:cve-id>
    <vuln:published-datetime>2011-05-04T18:55:01.467-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:04:44.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-05-05T08:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/1116" xml:lang="en">ADV-2011-1116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/1115" xml:lang="en">ADV-2011-1115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/control_systems/pdf/ICSA-12-137-02.pdf" xml:lang="en">http://www.us-cert.gov/control_systems/pdf/ICSA-12-137-02.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/47596" xml:lang="en">47596</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.indusoft.com/hotfixes/hotfixes.php" xml:lang="en">http://www.indusoft.com/hotfixes/hotfixes.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.advantechdirect.com/eMarketingPrograms/AStudio_Patch/AStudio7.0_Patch_Final.htm" xml:lang="en">http://www.advantechdirect.com/eMarketingPrograms/AStudio_Patch/AStudio7.0_Patch_Final.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2011-37/" xml:lang="en">http://secunia.com/secunia_research/2011-37/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2011-36/" xml:lang="en">http://secunia.com/secunia_research/2011-36/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/43116" xml:lang="en">43116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/42928" xml:lang="en">42928</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-249-03" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-249-03</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.</vuln:summary>
  </entry>
  <entry id="CVE-2011-0342">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:indusoft:web_studio:7.0b2:hotfix7.0.01.04"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:indusoft:web_studio:7.0b2:hotfix7.0.01.04</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-0342</vuln:cve-id>
    <vuln:published-datetime>2011-09-02T12:55:01.460-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:04:45.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-09-02T13:07:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/49403" xml:lang="en">49403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.indusoft.com/hotfixes/hotfixes.php" xml:lang="en">http://www.indusoft.com/hotfixes/hotfixes.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secunia.com/secunia_research/2011-61/" xml:lang="en">http://secunia.com/secunia_research/2011-61/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/44875" xml:lang="en">44875</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-11-273-02" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-11-273-02</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow remote attackers to execute arbitrary code via a long parameter to the (1) Open, (2) Close, or (3) SetCurrentLanguage method.</vuln:summary>
  </entry>
  <entry id="CVE-2011-1918">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ge:intelligent_platforms_proficy_historian:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ge:intelligent_platforms_proficy_historian:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ge:intelligent_platforms_proficy_historian:4.0</vuln:product>
      <vuln:product>cpe:/a:ge:intelligent_platforms_proficy_historian:3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-1918</vuln:cve-id>
    <vuln:published-datetime>2011-11-02T13:55:00.777-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:08:21.513-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-11-03T08:56:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/control_systems/pdf/ICSA-11-243-03.pdf" xml:lang="en">http://www.us-cert.gov/control_systems/pdf/ICSA-11-243-03.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/50475" xml:lang="en">50475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-11-243-03A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-11-243-03A</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic.</vuln:summary>
  </entry>
  <entry id="CVE-2011-5007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:3ssoftware:codesys:3.4:sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:3ssoftware:codesys:3.4:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-5007</vuln:cve-id>
    <vuln:published-datetime>2011-12-24T20:55:04.647-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:12:51.183-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2011-12-26T16:57:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-336-01A.pdf" xml:lang="en">http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-336-01A.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-336-01.pdf" xml:lang="en">http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-336-01.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="http://www.exploit-db.com/exploits/18187" xml:lang="en">18187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/47018" xml:lang="en">47018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://seclists.org/bugtraq/2011/Nov/178" xml:lang="en">20111129 Vulnerabilities in 3S CoDeSys 3.4 SP4 Patch 2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/77387" xml:lang="en">77387</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-320-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-320-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/codesys_1-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/codesys_1-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.</vuln:summary>
  </entry>
  <entry id="CVE-2012-1803">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ruggedcom:ros:3.10"/>
        <cpe-lang:fact-ref name="cpe:/o:ruggedcom:ros:3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:ruggedcom:ros:3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:ruggedcom:ros:3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:ruggedcom:ros:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ruggedcom:ros:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ruggedcom:ros:3.9</vuln:product>
      <vuln:product>cpe:/o:ruggedcom:ros:3.7</vuln:product>
      <vuln:product>cpe:/o:ruggedcom:ros:3.10</vuln:product>
      <vuln:product>cpe:/o:ruggedcom:ros:3.8</vuln:product>
      <vuln:product>cpe:/o:ruggedcom:ros:3.3</vuln:product>
      <vuln:product>cpe:/o:ruggedcom:ros:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-1803</vuln:cve-id>
    <vuln:published-datetime>2012-04-27T20:55:01.203-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:16:18.110-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-04-30T12:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-116-01A.pdf" xml:lang="en">http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-116-01A.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/MAPG-8RCPEN" xml:lang="en">http://www.kb.cert.org/vuls/id/MAPG-8RCPEN</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/889195" xml:lang="en">VU#889195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.wired.com/threatlevel/2012/04/ruggedcom-backdoor/" xml:lang="en">http://www.wired.com/threatlevel/2012/04/ruggedcom-backdoor/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/53215" xml:lang="en">53215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ruggedcom.com/productbulletin/ros-security-page/" xml:lang="en">http://www.ruggedcom.com/productbulletin/ros-security-page/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/fulldisclosure/2012/Apr/277" xml:lang="en">20120423 RuggedCom - Backdoor Accounts in my SCADA network? You don't say...</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-146-01A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-146-01A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://arstechnica.com/business/news/2012/04/backdoor-in-mission-critical-hardware-threatens-power-traffic-control-systems.ars" xml:lang="en">http://arstechnica.com/business/news/2012/04/backdoor-in-mission-critical-hardware-threatens-power-traffic-control-systems.ars</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2012-04/0186.html" xml:lang="en">20120423 RuggedCom - Backdoor Accounts in my SCADA network? You don't say...</vuln:reference>
    </vuln:references>
    <vuln:summary>RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) TELNET, (2) remote shell (aka rsh), or (3) serial-console session.</vuln:summary>
  </entry>
  <entry id="CVE-2012-1942">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:12.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:12.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:2.9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:12.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:12.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:2.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-1942</vuln:cve-id>
    <vuln:published-datetime>2012-06-05T19:55:01.687-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T23:20:30.270-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-06-06T12:40:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=748764" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=748764</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-45.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-45.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2012/mfsa2012-35.html" xml:lang="en">http://www.mozilla.org/security/announce/2012/mfsa2012-35.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allow local users to gain privileges by loading a DLL file in a privileged context.</vuln:summary>
  </entry>
  <entry id="CVE-2012-3792">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.30.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.24.200"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.23.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.21.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:wingp_pc_runtime:3.1.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.23.000</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.24.200</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.30.000</vuln:product>
      <vuln:product>cpe:/a:pro-face:wingp_pc_runtime:3.1.00</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.21.000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-3792</vuln:cve-id>
    <vuln:published-datetime>2012-06-25T13:55:01.113-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:19:19.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-06-26T08:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.hmisource.com/otasuke/news/2012/0606.html" xml:lang="en">https://www.hmisource.com/otasuke/news/2012/0606.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt" xml:lang="en">https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/53499" xml:lang="en">53499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/49172" xml:lang="en">49172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.org/adv/proservrex_1-adv.txt" xml:lang="en">http://aluigi.org/adv/proservrex_1-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (out-of-bounds read operation) via a crafted packet that triggers a certain Find Node check attempt.</vuln:summary>
  </entry>
  <entry id="CVE-2012-3793">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.30.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.24.200"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.23.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.21.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:wingp_pc_runtime:3.1.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.23.000</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.24.200</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.30.000</vuln:product>
      <vuln:product>cpe:/a:pro-face:wingp_pc_runtime:3.1.00</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.21.000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-3793</vuln:cve-id>
    <vuln:published-datetime>2012-06-25T13:55:01.193-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:19:25.580-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-06-26T09:04:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.hmisource.com/otasuke/news/2012/0606.html" xml:lang="en">https://www.hmisource.com/otasuke/news/2012/0606.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt" xml:lang="en">https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/75547" xml:lang="en">proserverex-overflow-dos(75547)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/53499" xml:lang="en">53499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/49172" xml:lang="en">49172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.org/adv/proservrex_1-adv.txt" xml:lang="en">http://aluigi.org/adv/proservrex_1-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode that triggers an incorrect memory allocation and a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2012-3794">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.30.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.24.200"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.23.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.21.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:wingp_pc_runtime:3.1.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.23.000</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.24.200</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.30.000</vuln:product>
      <vuln:product>cpe:/a:pro-face:wingp_pc_runtime:3.1.00</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.21.000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-3794</vuln:cve-id>
    <vuln:published-datetime>2012-06-25T13:55:01.253-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:19:25.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-06-26T09:11:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.hmisource.com/otasuke/news/2012/0606.html" xml:lang="en">https://www.hmisource.com/otasuke/news/2012/0606.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt" xml:lang="en">https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/75551" xml:lang="en">proserverex-exception-dos(75551)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/53499" xml:lang="en">53499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/49172" xml:lang="en">49172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.org/adv/proservrex_1-adv.txt" xml:lang="en">http://aluigi.org/adv/proservrex_1-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (unhandled exception and daemon crash) via a crafted packet with a certain opcode that triggers an invalid attempt to allocate a large amount of memory.</vuln:summary>
  </entry>
  <entry id="CVE-2012-3795">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.30.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.24.200"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.23.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.21.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:wingp_pc_runtime:3.1.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.23.000</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.24.200</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.30.000</vuln:product>
      <vuln:product>cpe:/a:pro-face:wingp_pc_runtime:3.1.00</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.21.000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-3795</vuln:cve-id>
    <vuln:published-datetime>2012-06-25T13:55:01.363-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:19:25.783-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-06-26T09:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.hmisource.com/otasuke/news/2012/0606.html" xml:lang="en">https://www.hmisource.com/otasuke/news/2012/0606.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt" xml:lang="en">https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/53499" xml:lang="en">53499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/49172" xml:lang="en">49172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.org/adv/proservrex_1-adv.txt" xml:lang="en">http://aluigi.org/adv/proservrex_1-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode and a large value in a size field.</vuln:summary>
  </entry>
  <entry id="CVE-2012-3796">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.30.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.24.200"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.23.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.21.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:wingp_pc_runtime:3.1.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.23.000</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.24.200</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.30.000</vuln:product>
      <vuln:product>cpe:/a:pro-face:wingp_pc_runtime:3.1.00</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.21.000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-3796</vuln:cve-id>
    <vuln:published-datetime>2012-06-25T13:55:01.410-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:19:25.970-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-06-26T09:20:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.hmisource.com/otasuke/news/2012/0606.html" xml:lang="en">https://www.hmisource.com/otasuke/news/2012/0606.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt" xml:lang="en">https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/53499" xml:lang="en">53499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/49172" xml:lang="en">49172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.org/adv/proservrex_1-adv.txt" xml:lang="en">http://aluigi.org/adv/proservrex_1-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to obtain sensitive information from daemon memory via a crafted packet with a certain opcode.</vuln:summary>
  </entry>
  <entry id="CVE-2012-3797">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.30.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.24.200"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.23.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:pro-server_ex:1.21.000"/>
        <cpe-lang:fact-ref name="cpe:/a:pro-face:wingp_pc_runtime:3.1.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.23.000</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.24.200</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.30.000</vuln:product>
      <vuln:product>cpe:/a:pro-face:wingp_pc_runtime:3.1.00</vuln:product>
      <vuln:product>cpe:/a:pro-face:pro-server_ex:1.21.000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-3797</vuln:cve-id>
    <vuln:published-datetime>2012-06-25T13:55:01.457-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:19:26.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-06-26T09:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.hmisource.com/otasuke/news/2012/0606.html" xml:lang="en">https://www.hmisource.com/otasuke/news/2012/0606.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt" xml:lang="en">https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/53499" xml:lang="en">53499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/49172" xml:lang="en">49172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.org/adv/proservrex_1-adv.txt" xml:lang="en">http://aluigi.org/adv/proservrex_1-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, does not properly check packet sizes before reusing packet memory buffers, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a short crafted packet with a certain opcode.</vuln:summary>
  </entry>
  <entry id="CVE-2012-4577">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:korenix:jetport:5601"/>
        <cpe-lang:fact-ref name="cpe:/h:korenix:jetport:5601f"/>
        <cpe-lang:fact-ref name="cpe:/h:korenix:jetport:5604"/>
        <cpe-lang:fact-ref name="cpe:/h:korenix:jetport:5604i"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:korenix:jetport:5601</vuln:product>
      <vuln:product>cpe:/h:korenix:jetport:5604</vuln:product>
      <vuln:product>cpe:/h:korenix:jetport:5604i</vuln:product>
      <vuln:product>cpe:/h:korenix:jetport:5601f</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-4577</vuln:cve-id>
    <vuln:published-datetime>2012-08-21T14:55:01.327-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:20:28.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-08-22T09:19:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/77992" xml:lang="en">jetport-default-password(77992)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/55196" xml:lang="en">55196</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalbond.com/2012/06/13/korenix-and-oring-insecurity" xml:lang="en">http://www.digitalbond.com/2012/06/13/korenix-and-oring-insecurity</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-297-02" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-297-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-263-02" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-263-02</vuln:reference>
    </vuln:references>
    <vuln:summary>The Linux firmware image on (1) Korenix Jetport 5600 series serial-device servers and (2) ORing Industrial DIN-Rail serial-device servers has a hardcoded password of "password" for the root account, which allows remote attackers to obtain administrative access via an SSH session.</vuln:summary>
  </entry>
  <entry id="CVE-2012-4690">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:rockwellautomation:ab_micrologix_controller:1400"/>
        <cpe-lang:fact-ref name="cpe:/h:rockwellautomation:ab_micrologix_controller:1100"/>
        <cpe-lang:fact-ref name="cpe:/h:rockwellautomation:ab_micrologix_controller:1200"/>
        <cpe-lang:fact-ref name="cpe:/h:rockwellautomation:ab_micrologix_controller:1500"/>
        <cpe-lang:fact-ref name="cpe:/h:rockwellautomation:plc-5_controller:-"/>
        <cpe-lang:fact-ref name="cpe:/h:rockwellautomation:slc_500_controller:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:rockwellautomation:ab_micrologix_controller:1500</vuln:product>
      <vuln:product>cpe:/h:rockwellautomation:ab_micrologix_controller:1100</vuln:product>
      <vuln:product>cpe:/h:rockwellautomation:ab_micrologix_controller:1200</vuln:product>
      <vuln:product>cpe:/h:rockwellautomation:slc_500_controller:-</vuln:product>
      <vuln:product>cpe:/h:rockwellautomation:ab_micrologix_controller:1400</vuln:product>
      <vuln:product>cpe:/h:rockwellautomation:plc-5_controller:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-4690</vuln:cve-id>
    <vuln:published-datetime>2012-12-08T10:55:01.007-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:20:35.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-12-10T11:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/control_systems/pdf/ICSA-12-342-01.pdf" xml:lang="en">http://www.us-cert.gov/control_systems/pdf/ICSA-12-342-01.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://rockwellautomation.custhelp.com/app/answers/detail/a_id/511407" xml:lang="en">https://rockwellautomation.custhelp.com/app/answers/detail/a_id/511407</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-342-01A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-342-01A</vuln:reference>
    </vuln:references>
    <vuln:summary>Rockwell Automation Allen-Bradley MicroLogix controller 1100, 1200, 1400, and 1500; SLC 500 controller platform; and PLC-5 controller platform, when Static status is not enabled, allow remote attackers to cause a denial of service via messages that trigger modification of status bits.</vuln:summary>
  </entry>
  <entry id="CVE-2012-4698">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:siemens:ros:3.11.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:siemens:rox_i_os:1.14.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:siemens:rox_ii_os:2.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:siemens:ruggedmax_os:4.2.1.4621.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:siemens:ruggedmax_os:4.2.1.4621.22</vuln:product>
      <vuln:product>cpe:/o:siemens:rox_i_os:1.14.5</vuln:product>
      <vuln:product>cpe:/o:siemens:rox_ii_os:2.3.0</vuln:product>
      <vuln:product>cpe:/o:siemens:ros:3.11.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-4698</vuln:cve-id>
    <vuln:published-datetime>2012-12-23T16:55:01.437-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:20:36.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-12-24T09:39:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/control_systems/pdf/ICSA-12-354-01.pdf" xml:lang="en">http://www.us-cert.gov/control_systems/pdf/ICSA-12-354-01.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-622607.pdf" xml:lang="en">https://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-622607.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ruggedcom.com/productbulletin/ros-security-page/" xml:lang="en">http://www.ruggedcom.com/productbulletin/ros-security-page/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-354-01A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-354-01A</vuln:reference>
    </vuln:references>
    <vuln:summary>Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic by leveraging the availability of these keys within ROS files at all customer installations.</vuln:summary>
  </entry>
  <entry id="CVE-2012-4704">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.18"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.19"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.2</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.6.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.7.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.3</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.2</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.3</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.4</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.20</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.18</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.19</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.5</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-4704</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T06:48:21.033-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:20:36.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T12:54:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-050-01A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-050-01A</vuln:reference>
    </vuln:references>
    <vuln:summary>Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.</vuln:summary>
  </entry>
  <entry id="CVE-2012-4705">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.18"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.19"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.2</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.6.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.7.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.3</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.2</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.3</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.4</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.20</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.18</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.19</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.5</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-4705</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T06:48:21.063-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:20:36.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T13:11:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-050-01A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-050-01A</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname.</vuln:summary>
  </entry>
  <entry id="CVE-2012-4706">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.18"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.19"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.2</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.6.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.7.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.3</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.2</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.3</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.4</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.20</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.18</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.19</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.5</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-4706</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T06:48:21.110-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:20:36.973-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T13:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-050-01A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-050-01A</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted packet that triggers a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2012-4707">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.18"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.19"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.2</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.6.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.7.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.3</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.2</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.3</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.4</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.18</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.19</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.5</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-4707</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T06:48:21.143-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:20:37.053-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T13:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-050-01A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-050-01A</vuln:reference>
    </vuln:references>
    <vuln:summary>3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory access.</vuln:summary>
  </entry>
  <entry id="CVE-2012-4708">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.18"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.19"/>
        <cpe-lang:fact-ref name="cpe:/a:3s-software:codesys_gateway-server:2.3.9.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.2</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.6.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.7.0</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.3</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.8.2</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.1</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.3</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.4</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.20</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.18</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.19</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.9.5</vuln:product>
      <vuln:product>cpe:/a:3s-software:codesys_gateway-server:2.3.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-4708</vuln:cve-id>
    <vuln:published-datetime>2013-02-24T06:48:21.190-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:20:37.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-25T13:02:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-050-01A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-050-01A</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.</vuln:summary>
  </entry>
  <entry id="CVE-2012-4711">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wellintech:kingview:6.52"/>
        <cpe-lang:fact-ref name="cpe:/a:wellintech:kingview:6.53"/>
        <cpe-lang:fact-ref name="cpe:/a:wellintech:kingview:6.55"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wellintech:kingview:6.53</vuln:product>
      <vuln:product>cpe:/a:wellintech:kingview:6.52</vuln:product>
      <vuln:product>cpe:/a:wellintech:kingview:6.55</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-4711</vuln:cve-id>
    <vuln:published-datetime>2013-02-15T07:09:27.820-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:20:37.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-15T09:59:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/pdf/ICSA-13-043-02.pdf" xml:lang="en">http://ics-cert.us-cert.gov/pdf/ICSA-13-043-02.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-043-02A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-043-02A</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.exe 65.50.2011.18049 in KingView 6.55 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted packet.</vuln:summary>
  </entry>
  <entry id="CVE-2012-4952">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:dentrix:g5:15.1.293"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dentrix:g5:15.1.293</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-4952</vuln:cve-id>
    <vuln:published-datetime>2013-05-01T08:00:07.190-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-21T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-01T08:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/JALR-8ZRHUK" xml:lang="en">http://www.kb.cert.org/vuls/id/JALR-8ZRHUK</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/948155" xml:lang="en">VU#948155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.dentrix.com/support/software-updates/g5.aspx" xml:lang="en">http://www.dentrix.com/support/software-updates/g5.aspx</vuln:reference>
    </vuln:references>
    <vuln:summary>Henry Schein Dentrix G5 before 15.1.294 has a single internal-database password that is shared across different customers' installations, which allows remote attackers to obtain sensitive information about patients by leveraging knowledge of this password from another installation.</vuln:summary>
  </entry>
  <entry id="CVE-2012-5409">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:siemens:sipass_integrated:mp2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:siemens:sipass_integrated:mp2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-5409</vuln:cve-id>
    <vuln:published-datetime>2012-11-01T06:44:47.717-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:21:26.053-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-11-01T13:31:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-938777.pdf" xml:lang="en">http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-938777.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/86129" xml:lang="en">86129</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/50900" xml:lang="en">50900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ioactive.com/pdfs/SIEMENS_Sipass_Integrated_Ethernet_Bus_Arbitrary_Pointer_Dereference_V4.pdf" xml:lang="en">http://ioactive.com/pdfs/SIEMENS_Sipass_Integrated_Ethernet_Bus_Arbitrary_Pointer_Dereference_V4.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-12-305-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-12-305-01</vuln:reference>
    </vuln:references>
    <vuln:summary>AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.</vuln:summary>
  </entry>
  <entry id="CVE-2012-6137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:5::server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:5.0::client"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_eus:5.9.z::server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_hpc_node:6"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_long_life:5.9::server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_server_aus:6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_server_eus:6.4.z"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_workstation:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux_eus:5.9.z::server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_server_aus:6.4</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_server:6.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_server_eus:6.4.z</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_hpc_node:6</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:5::server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_workstation:6.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:5.0::client</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_long_life:5.9::server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-6137</vuln:cve-id>
    <vuln:published-datetime>2013-05-21T14:55:01.653-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T09:09:48.957-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T08:55:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=885130" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=885130</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/84020" xml:lang="en">redhat-ssl-cve20126137-sec-bypass(84020)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id/1028520" xml:lang="en">1028520</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/59674" xml:lang="en">59674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/53330" xml:lang="en">53330</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0788.html" xml:lang="en">RHSA-2013:0788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/93058" xml:lang="en">93058</vuln:reference>
    </vuln:references>
    <vuln:summary>rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:patrick_masotta:serva32:2.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:patrick_masotta:serva32:2.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0145</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.263-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T11:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/127108" xml:lang="en">VU#127108</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in a read request.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.1:pre"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.2:pre"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.12:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.13:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.10:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.17</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.1:pre</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.13</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.5:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.16</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.13:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.14</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.5:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.4:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.12</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.18</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.2:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.2:pre</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.12:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.10:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.11</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.4:rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0155</vuln:cve-id>
    <vuln:published-datetime>2013-01-13T17:55:00.900-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:22:30.130-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-14T13:58:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://groups.google.com/group/rubyonrails-security/msg/bc6f13dafe130ee9?dmode=source&amp;output=gplain" xml:lang="en">[rubyonrails-security] 20130108 Unsafe Query Generation Risk in Ruby on Rails (CVE-2013-0155)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2609" xml:lang="en">DSA-2609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0155.html" xml:lang="en">RHSA-2013:0155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0154.html" xml:lang="en">RHSA-2013:0154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A</vuln:reference>
    </vuln:references>
    <vuln:summary>Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660 and CVE-2012-2694.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.0.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.0.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:rails:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.14.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.12.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.13.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.14.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.13.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.14.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.14.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.1:pre"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.2:pre"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.12:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.13:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.10:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:2.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyonrails:ruby_on_rails:3.2.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.1.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.11.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.6.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.14</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.10.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.2.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.5.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.14.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.8.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.16</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.9.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.9</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.14</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.13.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.14.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.4:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.9.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.2.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.14.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.2.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.12</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.9.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.0.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.12.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.2:pre</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.14.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.13.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.12:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.7.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.10:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.11</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.10</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.11.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.4:rc</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.9.4.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.0.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.17</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.7</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.1:pre</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.0.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.2.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.9.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.13</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.12.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.5:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.12</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.1.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.13:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.8.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0:rc6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.5.6</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.1:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.13</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.5:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.6:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.5.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.0.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.11</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.9.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.18</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.2:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.1.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.0.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.1.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.8</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:rails:1.2.4</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.3.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc2</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:1.9.5</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.9:rc1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.5.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.0.3</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.10.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:0.6.0</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:2.1.1</vuln:product>
      <vuln:product>cpe:/a:rubyonrails:ruby_on_rails:3.2.4:rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0156</vuln:cve-id>
    <vuln:published-datetime>2013-01-13T17:55:00.947-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:22:30.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-01-14T13:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/628463" xml:lang="en">VU#628463</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/380039" xml:lang="en">VU#380039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://groups.google.com/group/rubyonrails-security/msg/c1432d0f8c70e89d?dmode=source&amp;output=gplain" xml:lang="en">[rubyonrails-security] 20130108 Multiple vulnerabilities in parameter parsing in Action Pack (CVE-2013-0156)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://community.rapid7.com/community/metasploit/blog/2013/01/09/serialization-mischief-in-ruby-land-cve-2013-0156" xml:lang="en">https://community.rapid7.com/community/metasploit/blog/2013/01/09/serialization-mischief-in-ruby-land-cve-2013-0156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.insinuator.net/2013/01/rails-yaml/" xml:lang="en">http://www.insinuator.net/2013/01/rails-yaml/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2013/dsa-2604" xml:lang="en">DSA-2604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/" xml:lang="en">http://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0155.html" xml:lang="en">RHSA-2013:0155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0154.html" xml:lang="en">RHSA-2013:0154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0153.html" xml:lang="en">RHSA-2013:0153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html" xml:lang="en">APPLE-SA-2013-03-14-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A</vuln:reference>
    </vuln:references>
    <vuln:summary>active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0711">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:windriver:vxworks:6.7</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.5</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.8</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.6</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0711</vuln:cve-id>
    <vuln:published-datetime>2013-03-20T14:55:01.700-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:23:03.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T13:20:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVNDB</vuln:source>
      <vuln:reference href="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000018" xml:lang="en">JVNDB-2013-000018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN45545972/index.html" xml:lang="en">JVN#45545972</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN45545972/995359/index.html" xml:lang="en">http://jvn.jp/en/jp/JVN45545972/995359/index.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-091-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-091-01</vuln:reference>
    </vuln:references>
    <vuln:summary>IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to cause a denial of service (daemon outage) via a crafted authentication request.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0713">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:windriver:vxworks:6.7</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.5</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.8</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.6</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0713</vuln:cve-id>
    <vuln:published-datetime>2013-03-20T14:55:01.747-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:23:04.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T13:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVNDB</vuln:source>
      <vuln:reference href="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000020" xml:lang="en">JVNDB-2013-000020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN52492830/index.html" xml:lang="en">JVN#52492830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN52492830/995359/index.html" xml:lang="en">http://jvn.jp/en/jp/JVN52492830/995359/index.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-091-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-091-01</vuln:reference>
    </vuln:references>
    <vuln:summary>IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote authenticated users to cause a denial of service (daemon outage) via a crafted pty request.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0714">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:windriver:vxworks:6.7</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.5</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.8</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.6</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0714</vuln:cve-id>
    <vuln:published-datetime>2013-03-20T14:55:01.767-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:23:04.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T13:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVNDB</vuln:source>
      <vuln:reference href="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000021" xml:lang="en">JVNDB-2013-000021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN20671901/index.html" xml:lang="en">JVN#20671901</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN20671901/995359/index.html" xml:lang="en">http://jvn.jp/en/jp/JVN20671901/995359/index.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-091-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-091-01</vuln:reference>
    </vuln:references>
    <vuln:summary>IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of service (daemon hang) via a crafted public-key authentication request.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0715">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:windriver:vxworks:6.7</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.5</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.8</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.6</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0715</vuln:cve-id>
    <vuln:published-datetime>2013-03-20T14:55:01.787-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:23:04.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T13:32:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVNDB</vuln:source>
      <vuln:reference href="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000022" xml:lang="en">JVNDB-2013-000022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN65923092/index.html" xml:lang="en">JVN#65923092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN65923092/995359/index.html" xml:lang="en">http://jvn.jp/en/jp/JVN65923092/995359/index.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-091-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-091-01</vuln:reference>
    </vuln:references>
    <vuln:summary>The WebCLI component in Wind River VxWorks 5.5 through 6.9 allows remote authenticated users to cause a denial of service (CLI session crash) via a crafted command string.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0716">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:windriver:vxworks:6.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:windriver:vxworks:6.7</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.5</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.8</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.6</vuln:product>
      <vuln:product>cpe:/o:windriver:vxworks:6.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0716</vuln:cve-id>
    <vuln:published-datetime>2013-03-20T14:55:01.807-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T23:23:04.317-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-21T13:36:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVNDB</vuln:source>
      <vuln:reference href="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000023" xml:lang="en">JVNDB-2013-000023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN41022517/index.html" xml:lang="en">JVN#41022517</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN41022517/995359/index.html" xml:lang="en">http://jvn.jp/en/jp/JVN41022517/995359/index.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ics-cert.us-cert.gov/advisories/ICSA-13-091-01" xml:lang="en">http://ics-cert.us-cert.gov/advisories/ICSA-13-091-01</vuln:reference>
    </vuln:references>
    <vuln:summary>The web server in Wind River VxWorks 5.5 through 6.9 allows remote attackers to cause a denial of service (daemon crash) via a crafted URI.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0801">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0801</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.633-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T09:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=866544" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=866544</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=864558" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=864558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=852315" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=852315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=849597" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=849597</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=808402" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=808402</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=787283" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=787283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-41.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-41.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0941">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rsa:authentication_api:8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:rsa:securid_web_agent:5.3.4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apache:http_server"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:rsa:securid_web_agent:5.3.4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rsa:pluggable_authentication_module:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:rsa:authentication_agent:6.1.3"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rsa:pluggable_authentication_module:6.0</vuln:product>
      <vuln:product>cpe:/a:rsa:securid_web_agent:5.3.4</vuln:product>
      <vuln:product>cpe:/a:rsa:authentication_api:8.1</vuln:product>
      <vuln:product>cpe:/a:rsa:authentication_agent:6.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0941</vuln:cve-id>
    <vuln:published-datetime>2013-05-22T09:29:45.513-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T10:08:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2013-05/0064.html" xml:lang="en">20130516 ESA-2013-029: RSA SecurID Sensitive Information Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0942">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:emc:rsa_authentication_agent:7.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:emc:rsa_authentication_agent:7.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apache:http_server"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:emc:rsa_authentication_agent:7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0942</vuln:cve-id>
    <vuln:published-datetime>2013-05-22T09:29:55.837-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T10:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2013-05/0043.html" xml:lang="en">20130510 ESA-2013-031: RSA Authentication Agent Cross-Site Scripting (XSS) Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Agent 7.1 before 7.1.1 for Web for Internet Information Services, and 7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0991">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0991</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.410-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T11:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0992">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:sp2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0992</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.447-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0993">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0993</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.480-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0994">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0994</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.543-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:32:11.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0995">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0995</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.580-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:35:32.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0996">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0996</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.613-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:35:54.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0997">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0997</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.647-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:37:21.217-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:36:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0998">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0998</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.677-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:38:04.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:37:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-0999">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-0999</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.710-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:42:17.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:38:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1000">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1000</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.750-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:39:43.833-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:38:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1001</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.787-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:40:33.927-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1002</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.817-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:41:15.730-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:40:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1003</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.850-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:42:07.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1004</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.883-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:42:48.847-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1005</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.920-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:43:34.063-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:42:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1006</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:34.973-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:43:49.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1007</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:35.007-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:44:17.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1008</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:35.040-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:46:09.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1010</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:35.097-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:45:03.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:44:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1011</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:35.180-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:46:02.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.2.2.12"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.1.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.1.10"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.4.0.80"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.5.1.42"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:10.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:9.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:8.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.3.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.4.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.6.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:6.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.2.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.5.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:4.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:itunes:11.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.8"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.0"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.4"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.1.42</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1.10</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.8.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.0.80</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:11.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.2.2.12</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.6.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.7</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.9.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:8.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:9.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:4.7.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.4.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.5.0</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:7.6.1</vuln:product>
      <vuln:product>cpe:/a:apple:itunes:10.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1014</vuln:cve-id>
    <vuln:published-datetime>2013-05-20T10:44:35.207-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-20T12:49:58.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.9</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-20T12:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5766" xml:lang="en">http://support.apple.com/kb/HT5766</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2013/May/msg00000.html" xml:lang="en">APPLE-SA-2013-05-16-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7.3:ftf2"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7.3:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7:refresh6"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7:sp4_patch4"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7:sp4_patch3"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7:sp4_patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7:sp4_patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7.3:ftf4"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:imanager:2.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:imanager:2.7:sp4_patch1</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7.3:ftf2</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7:sp4</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7:sp5</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7:sp4_patch4</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7.3:ftf4</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7.1</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7:refresh6</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7.3:sp3</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7.3</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7.2</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7:sp6</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7.4</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7:sp4_patch2</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7.5</vuln:product>
      <vuln:product>cpe:/a:novell:imanager:2.7:sp4_patch3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1088</vuln:cve-id>
    <vuln:published-datetime>2013-04-24T06:28:37.790-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-24T08:37:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.novell.com/show_bug.cgi?id=726260" xml:lang="en">https://bugzilla.novell.com/show_bug.cgi?id=726260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.novell.com/support/kb/doc.php?id=7010166" xml:lang="en">http://www.novell.com/support/kb/doc.php?id=7010166</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:ace_application_controle_engine_module:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:ace_application_controle_engine_module:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1175</vuln:cve-id>
    <vuln:published-datetime>2013-05-15T23:36:22.627-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T08:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1175" xml:lang="en">20130514 Cisco ACE Log Retention Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>The SSL logging daemon in the Application Control Engine module in Cisco ACE allows remote attackers to cause a denial of service (disk consumption) via a large number of SSL connections that trigger log entries, aka Bug ID CSCug78957.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1188">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_communications_manager"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:unified_communications_manager</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1188</vuln:cve-id>
    <vuln:published-datetime>2013-05-15T23:36:22.690-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T08:57:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1188" xml:lang="en">20130514 Cisco Unified Communications Manager Authentication Denial of Service</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Unified Communications Manager (CUCM) does not properly limit the rate of authentication attempts, which allows remote attackers to cause a denial of service (application slowdown) via a series of requests, aka Bug ID CSCud39515.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1200">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_system:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:secure_access_control_system:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1200</vuln:cve-id>
    <vuln:published-datetime>2013-05-15T23:36:22.710-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T09:02:46.077-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T09:01:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1200" xml:lang="en">20130515 Cisco Secure Access Control System Session Fixation Web Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Session fixation vulnerability in Cisco Secure Access Control System (ACS) allows remote attackers to hijack web sessions via unspecified vectors, aka Bug ID CSCud95787.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1236">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:cisco:telepresence_supervisor_mse_8050_software:2.2%281.17%29"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/h:cisco:telepresence_supervisor_mse_8050:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:telepresence_supervisor_mse_8050_software:2.2%281.17%29</vuln:product>
      <vuln:product>cpe:/h:cisco:telepresence_supervisor_mse_8050:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1236</vuln:cve-id>
    <vuln:published-datetime>2013-05-15T23:36:22.727-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T09:13:47.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T09:07:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130515-mse" xml:lang="en">20130515 Cisco TelePresence Supervisor MSE 8050 Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco TelePresence Supervisor MSE 8050 before 2.3(1.31) allows remote attackers to cause a denial of service (CPU consumption or device reload) by establishing TCP connections at a high rate, aka Bug IDs CSCuf76076 and CSCuf79763.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1244">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:webex_social:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:webex_social:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1244</vuln:cve-id>
    <vuln:published-datetime>2013-05-15T23:36:22.747-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T09:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1244" xml:lang="en">20130514 WebEx Social Allows JavaScript URLs in Links Attached to Posts</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the portal module in Cisco WebEx Social allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL in the link field in a post, aka Bug ID CSCue67199.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1245">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:webex_social:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:webex_social:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1245</vuln:cve-id>
    <vuln:published-datetime>2013-05-15T23:36:22.767-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T09:55:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1245" xml:lang="en">20130514 WebEx Social Client-Side Restriction Bypass Attribute Change Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>The user-management page in Cisco WebEx Social relies on client-side validation of values in the Screen Name, First Name, Middle Name, Last Name, Email Address, and Job Title fields, which allows remote authenticated users to bypass intended access restrictions via crafted requests, aka Bug ID CSCue67190.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1301">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2007:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2010:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:visio:2007:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2010:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1301</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:33.410-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T09:51:32.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T09:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-044" xml:lang="en">MS13-044</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1305">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2012:-</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:-:-:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_rt:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1305</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:33.447-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T10:07:21.027-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T10:05:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-039" xml:lang="en">MS13-039</vuln:reference>
    </vuln:references>
    <vuln:summary>HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1311">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1311</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:34.077-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T10:46:32.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T10:32:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-037" xml:lang="en">MS13-037</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1313">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1313</vuln:cve-id>
    <vuln:published-datetime>2013-02-13T07:04:14.087-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T23:35:27.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-02-13T13:56:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-020" xml:lang="en">MS13-020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-037" xml:lang="en">MS13-037</vuln:reference>
    </vuln:references>
    <vuln:summary>Object Linking and Embedding (OLE) Automation in Microsoft Windows XP SP3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted RTF document, aka "OLE Automation Remote Code Execution Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1318">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2003:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:publisher:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1318</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:34.153-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T10:52:58.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T10:52:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-042" xml:lang="en">MS13-042</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Publisher Corrupt Interface Pointer Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1319">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2003:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:publisher:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1319</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:34.177-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T10:56:31.287-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T10:55:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-042" xml:lang="en">MS13-042</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Handling Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1320">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2003:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:publisher:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1320</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:34.193-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T10:57:39.183-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T10:57:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-042" xml:lang="en">MS13-042</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Buffer Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1322">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2003:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:publisher:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1322</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:34.230-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T11:04:09.847-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T11:01:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-042" xml:lang="en">MS13-042</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Invalid Range Check Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1328">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2007:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2010:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:publisher:2007:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher:2010:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1328</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:34.287-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T11:25:48.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T11:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-042" xml:lang="en">MS13-042</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect pointer handling, aka "Publisher Pointer Handling Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1329">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2003:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:publisher:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1329</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:34.303-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T11:13:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-042" xml:lang="en">MS13-042</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer underflow, aka "Publisher Buffer Underflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1332">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2012:-"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_rt:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2012:-</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:-:-:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_rt:-</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:-:-:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1332</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:34.323-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T12:19:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-046" xml:lang="en">MS13-046</vuln:reference>
    </vuln:references>
    <vuln:summary>dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1335">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word_viewer:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:word:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:word_viewer:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1335</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:34.383-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T12:33:07.437-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T12:31:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-043" xml:lang="en">MS13-043</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1336">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1336</vuln:cve-id>
    <vuln:published-datetime>2013-05-14T23:36:34.403-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T12:59:21.723-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-15T12:44:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-040" xml:lang="en">MS13-040</vuln:reference>
    </vuln:references>
    <vuln:summary>The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1347">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:sp2:professional:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1347</vuln:cve-id>
    <vuln:published-datetime>2013-05-05T07:07:00.527-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T23:35:29.683-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-06T09:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/advisory/2847140" xml:lang="en">http://technet.microsoft.com/security/advisory/2847140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-038" xml:lang="en">MS13-038</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1389">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:9.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:10.0:update_1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:10.0:update_3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:10.0:update_4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:9.0.1:update_9"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:9.0:update_10"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:9.0.2:update_4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:coldfusion:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:coldfusion:9.0.2:update_4</vuln:product>
      <vuln:product>cpe:/a:adobe:coldfusion:9.0:update_10</vuln:product>
      <vuln:product>cpe:/a:adobe:coldfusion:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:coldfusion:9.0.1:update_9</vuln:product>
      <vuln:product>cpe:/a:adobe:coldfusion:10.0:update_4</vuln:product>
      <vuln:product>cpe:/a:adobe:coldfusion:10.0:update_1</vuln:product>
      <vuln:product>cpe:/a:adobe:coldfusion:9.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:coldfusion:9.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:coldfusion:10.0:update_3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1389</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.693-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T09:56:27.933-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T09:54:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-13.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-13.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 11, 9.0.1 before Update 10, 9.0.2 before Update 5, and 10 before Update 10 allows remote attackers to execute arbitrary code via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1669">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1669</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.720-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=865948" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=865948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=855236" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=855236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=854001" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=854001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=843434" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=843434</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=837324" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=837324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=837007" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=837007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=834526" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=834526</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=826588" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=826588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=826392" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=826392</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=826104" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=826104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=822910" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=822910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=821850" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=821850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=821479" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=821479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=819775" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=819775</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=814552" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=814552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=803228" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=803228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=791432" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=791432</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-41.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-41.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1670">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1670</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.777-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T10:03:47.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=853709" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=853709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-42.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-42.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content level constructors, which allows remote attackers to bypass certain read-only restrictions and conduct cross-site scripting (XSS) attacks via a crafted web site.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1671">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1671</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.797-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T09:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=842255" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=842255</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-43.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-43.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Mozilla Firefox before 21.0 does not properly implement the INPUT element, which allows remote attackers to obtain the full pathname via a crafted web site.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1672">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1672</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.817-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T10:16:44.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=850492" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=850492</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-44.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-44.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors involving junctions.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1673">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1673</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.840-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:11:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=854088" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=854088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-45.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-45.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situations involving upgrades from older Firefox versions, which allows local users to gain privileges by leveraging write access to a "trusted path."</vuln:summary>
  </entry>
  <entry id="CVE-2013-1674">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1674</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.857-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=860971" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=860971</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-46.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-46.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code via vectors involving an onresize event during the playing of a video.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1675">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1675</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.877-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=866825" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=866825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-47.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-47.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1676">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1676</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.900-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:19:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=818454" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=818454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-48.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-48.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The SelectionIterator::GetNextSegment function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1677">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1677</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.923-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T10:41:21.463-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=826163" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=826163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-48.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-48.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The gfxSkipCharsIterator::SetOffsets function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1678">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1678</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.947-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=839745" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=839745</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-48.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-48.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The _cairo_xlib_surface_add_glyph function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (invalid write operation) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1679">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1679</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.970-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=848237" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=848237</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-48.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-48.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1680">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1680</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:30.990-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=850931" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=850931</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-48.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-48.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1681">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:19.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:20.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird_esr:17.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:20.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird_esr:17.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:19.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox_esr:17.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1681</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.017-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:33:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=851781" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=851781</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2013/mfsa2013-48.html" xml:lang="en">http://www.mozilla.org/security/announce/2013/mfsa2013-48.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1964">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:xen:xen:4.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:xen:xen:4.0.0</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.0.2</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.0.3</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.5</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.4</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.3</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.2</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.1</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.0.4</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.1.0</vuln:product>
      <vuln:product>cpe:/o:xen:xen:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1964</vuln:cve-id>
    <vuln:published-datetime>2013-05-21T14:55:01.907-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T09:07:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id/1028459" xml:lang="en">1028459</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/59293" xml:lang="en">59293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/04/18/9" xml:lang="en">[oss-security] 20130418 Xen Security Advisory 50 (CVE-2013-1964) - grant table hypercall acquire/release imbalance</vuln:reference>
    </vuln:references>
    <vuln:summary>Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possible have other impacts via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-1977">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openstack:devstack:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openstack:devstack:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-1977</vuln:cve-id>
    <vuln:published-datetime>2013-05-21T14:55:02.163-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T09:12:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugs.launchpad.net/devstack/+bug/1168252" xml:lang="en">https://bugs.launchpad.net/devstack/+bug/1168252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/04/23/7" xml:lang="en">[oss-security] 20130423 Re: CVE-2013-1977 - OpenStack keystone.conf insecure file permissions</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/04/19/2" xml:lang="en">[oss-security] 20130419 CVE-2013-1977 - OpenStack keystone.conf insecure file permissions</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openstack:keystone:2013.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openstack:keystone:2013.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2006</vuln:cve-id>
    <vuln:published-datetime>2013-05-21T14:55:02.340-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T09:23:17.100-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T09:20:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://github.com/openstack/keystone/commit/c5037dd6b82909efaaa8720e8cfa8bdb8b4a0edd" xml:lang="en">https://github.com/openstack/keystone/commit/c5037dd6b82909efaaa8720e8cfa8bdb8b4a0edd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.launchpad.net/ossn/+bug/1168252" xml:lang="en">https://bugs.launchpad.net/ossn/+bug/1168252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.launchpad.net/keystone/+bug/1172195" xml:lang="en">https://bugs.launchpad.net/keystone/+bug/1172195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/59411" xml:lang="en">59411</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/04/24/2" xml:lang="en">[oss-security] 20130424 Re: CVE-2013-2006 OpenStack keystone LDAP password disclosure in log files</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/04/24/1" xml:lang="en">[oss-security] 20130423 CVE-2013-2006 OpenStack keystone LDAP password disclosure in log files</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2013-0806.html" xml:lang="en">RHSA-2013:0806</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:qemu:qemu:1.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qemu:qemu:1.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2007</vuln:cve-id>
    <vuln:published-datetime>2013-05-21T14:55:02.623-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T09:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=956082" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=956082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/84047" xml:lang="en">qemu-cve20132007-priv-esc(84047)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id/1028521" xml:lang="en">1028521</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/59675" xml:lang="en">59675</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/05/06/5" xml:lang="en">[oss-security] 20130506 Xen Security Advisory 51 (CVE-2013-2007) - qemu guest agent (qga) insecure file permissions</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/53325" xml:lang="en">53325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/93032" xml:lang="en">93032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.qemu.org/?p=qemu.git;a=commit;h=c689b4f1bac352dcfd6ecb9a1d45337de0f1de67" xml:lang="en">http://git.qemu.org/?p=qemu.git;a=commit;h=c689b4f1bac352dcfd6ecb9a1d45337de0f1de67</vuln:reference>
    </vuln:references>
    <vuln:summary>The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows local users to read and write to these files.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openstack:keystone:2012.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openstack:keystone:2013.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openstack:keystone:2012.1</vuln:product>
      <vuln:product>cpe:/a:openstack:keystone:2013.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2059</vuln:cve-id>
    <vuln:published-datetime>2013-05-21T14:55:02.867-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T09:54:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.launchpad.net/keystone/+bug/1166670" xml:lang="en">https://bugs.launchpad.net/keystone/+bug/1166670</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/84135" xml:lang="en">keystone-cve20132059-security-bypass(84135)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/59787" xml:lang="en">59787</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/05/09/4" xml:lang="en">[oss-security] 20130509 RE: [Openstack] [OSSA 2013-011] Keystone tokens not immediately invalidated when user is deleted (CVE-2013-2059)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.openwall.com/lists/oss-security/2013/05/09/3" xml:lang="en">[oss-security] 20130509 [OSSA 2013-011] Keystone tokens not immediately invalidated when user is deleted (CVE-2013-2059)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/53339" xml:lang="en">53339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECUNIA</vuln:source>
      <vuln:reference href="http://secunia.com/advisories/53326" xml:lang="en">53326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://osvdb.org/93134" xml:lang="en">93134</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2311">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:2.0.1-11"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.99.5"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.99.7"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.99.4"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.99.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.99.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.99.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.98.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.98.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.97.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.96.4"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.96.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.96.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.95.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.94.6"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.94.5"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.94.4"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.94.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.94.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.94.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.93.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.93.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.92.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.91.6"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.91.5"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.91.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.91.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.90.6"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.90.5"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.90.4"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.90.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.90.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.89.5"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.89.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.88.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.87.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.87.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.87.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.86.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.86.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.85.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.85.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.84.4"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.84.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.83.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.83.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.82.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.81.5"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.81.4"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.81.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.81.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.81.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.80.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.79.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.79.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.78.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.78.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.77.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.77.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.77.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.76.5"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.76.4"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.76.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.76.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web2py:web2py:1.76.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web2py:web2py:1.94.4</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.84.4</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.76.4</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:2.0.1-11</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.83.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.91.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.99.3</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.91.6</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.90.5</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.88.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.96.4</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.76.5</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.81.3</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.76.3</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.86.3</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.81.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.90.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.93.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.96.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:2.1.0</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.90.6</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.80.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.90.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.78.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.82.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.94.6</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.90.4</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.94.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.98.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.99.4</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.99.5</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.87.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.79.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.92.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.89.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.85.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.98.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.76.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.94.3</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.76.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.99.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.77.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.79.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.96.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.93.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.89.5</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.94.5</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.99.7</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.91.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.85.3</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.99.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.81.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.81.4</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.77.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.78.3</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.86.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.94.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.97.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.87.3</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.83.2</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:2.2.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.77.3</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.87.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.91.5</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.84.1</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.81.5</vuln:product>
      <vuln:product>cpe:/a:web2py:web2py:1.95.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2311</vuln:cve-id>
    <vuln:published-datetime>2013-05-22T09:29:55.850-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T10:31:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://groups.google.com/group/web2py/msg/ca10dffa2f0b2731?dmode=source&amp;output=gplain" xml:lang="en">[web2py] 20121214 web2py 2.3.1 is out</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVNDB</vuln:source>
      <vuln:reference href="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000040" xml:lang="en">JVNDB-2013-000040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN10461119/index.html" xml:lang="en">JVN#10461119</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2405">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:primavera_products_suite:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:primavera_products_suite:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:primavera_products_suite:8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:primavera_products_suite:7.0</vuln:product>
      <vuln:product>cpe:/a:oracle:primavera_products_suite:8.1</vuln:product>
      <vuln:product>cpe:/a:oracle:primavera_products_suite:8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2405</vuln:cve-id>
    <vuln:published-datetime>2013-04-17T13:55:07.057-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-04-18T09:51:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 7.0, 8.1, and 8.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Web Access.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2549">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2549</vuln:cve-id>
    <vuln:published-datetime>2013-03-11T06:55:01.053-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T23:28:24.990-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T11:53:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://twitter.com/thezdi/statuses/309771882612281344" xml:lang="en">http://twitter.com/thezdi/statuses/309771882612281344</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157" xml:lang="en">http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers to execute arbitrary code via vectors related to a "break into the sandbox," as demonstrated by George Hotz during a Pwn2Own competition at CanSecWest 2013.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2550">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2550</vuln:cve-id>
    <vuln:published-datetime>2013-03-11T06:55:01.060-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T23:28:25.067-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T12:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://twitter.com/thezdi/statuses/309771882612281344" xml:lang="en">http://twitter.com/thezdi/statuses/309771882612281344</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157" xml:lang="en">http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Adobe Reader 11.0.02 allows attackers to bypass the sandbox protection mechanism via unknown vectors, as demonstrated by George Hotz during a Pwn2Own competition at CanSecWest 2013.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2551">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x86"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:-:-:x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2551</vuln:cve-id>
    <vuln:published-datetime>2013-03-11T06:55:01.070-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-15T23:36:06.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-03-16T09:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://twitter.com/VUPEN/statuses/309479075385327617" xml:lang="en">http://twitter.com/VUPEN/statuses/309479075385327617</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://twitter.com/thezdi/statuses/309452625173176320" xml:lang="en">http://twitter.com/thezdi/statuses/309452625173176320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS13-037" xml:lang="en">MS13-037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157" xml:lang="en">http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2718">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2718</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.037-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:36:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2719">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2719</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.060-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2720">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2720</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.080-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T10:57:29.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:56:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2721">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2721</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.100-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:50:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2722">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2722</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.120-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T10:51:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2723">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2723</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.140-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T11:12:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2724">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2724</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.160-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T11:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2725">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2725</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.180-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T11:17:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2726">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2726</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.200-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T09:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2727">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2727</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.220-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T11:20:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2729.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2728">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.25"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.29"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.43"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.5"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.7"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.23"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.15"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.11"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.20"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.50"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.48"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.19"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.61"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.16"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.67"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.18"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.63"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.10"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.51"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.181.26"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.181.22"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.181.34"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.181.16"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.181.23"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.181.14"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.157.51"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.159.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.152.33"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.154.13"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.152.26"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.152.32"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.154.25"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.156.12"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.153.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.152"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.106.16"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.105.6"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.106.17"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.52.15"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.53.64"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.52.14.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.82.76"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.92.8"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.95.2"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.85.3"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.95.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.52.14"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.102.64"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.92.10"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.15.3"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.12.36"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.42.34"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.0.584"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.45.2"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.32.18"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.12.10"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.2.54"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.22.87"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.280"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.112.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.260.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.246.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.125.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.152.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.151.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.18d60"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.16"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.47.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.45.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.28"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.277.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.125.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.20"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.114.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.28.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.262.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.115.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.283.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.20.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.31.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.31"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.124.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.159.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.48.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.155.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.33.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.22.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.42.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.24.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.34.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.39.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.35.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.25"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.63"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.66.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.68.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.67.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.73.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.24.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.53.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.60.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.61.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.14.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.19.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.69.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.70.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:6.0.21.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:6.0.79"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.238"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.3.300.271"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.3.300.270"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.111.8"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.102.59"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.233"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.115.7"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.5.502.136"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.115.34"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.262"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.5.502.146"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.235"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.5.502.135"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.5.502.149"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.0.1.153"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.273"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.6.602.171"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.0.1.152"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.261"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.236"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.102.62"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.258"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.5.502.110"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.251"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.228"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.102.63"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.4.402.265"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.3.300.257"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.3.300.262"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.3.300.265"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.3.300.268"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.3.300.273"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.4.402.278"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.102.55"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.4.402.287"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.6.602.180"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.243"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.223"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.270"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.6.602.168"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.6.602.167"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.68"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.75"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.7.700.169"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.25"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.29"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.43"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.5"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.7"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.23"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.15"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.11"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.20"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.50"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.48"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.19"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.61"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.16"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.67"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.18"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.63"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.10"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.51"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.181.26"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.181.22"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.181.34"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.181.16"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.181.23"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.181.14"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.157.51"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.159.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.152.33"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.154.13"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.152.26"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.152.32"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.154.25"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.156.12"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.153.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.2.152"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.106.16"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.105.6"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.106.17"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.52.15"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.53.64"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.52.14.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.82.76"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.92.8"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.95.2"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.85.3"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.95.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.52.14"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.102.64"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.1.92.10"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.15.3"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.12.36"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.42.34"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.0.584"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.45.2"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.32.18"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.12.10"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.2.54"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.0.22.87"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.280"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.112.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.260.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.246.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.125.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.152.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.151.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.18d60"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.16"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.47.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.45.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.28"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.277.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.125.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.20"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.114.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.28.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.262.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.115.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.283.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.20.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.31.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.31"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.124.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.159.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.48.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.155.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.33.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.22.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.42.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.24.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.34.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.39.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.35.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.25"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.63"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.66.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.68.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.67.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.73.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.24.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.53.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.60.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.61.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.14.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.19.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.69.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:7.0.70.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:6.0.21.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:6.0.79"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.238"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.111.8"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.102.59"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.233"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.115.7"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.115.34"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.262"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.0"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.235"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.0.1.153"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.273"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.0.1.152"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.261"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.236"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.102.62"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.258"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.251"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.228"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.102.63"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.102.55"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.243"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.223"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.270"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.68"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:10.3.183.75"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.275"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.2.202.280"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.111.8"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.111.44"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.111.50"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.2.3"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.2"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.3.3"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.3.4"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.3:rev1"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.2:rev1"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.3.7"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.2.1"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.2.2"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.1"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.3"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.3.5"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.3.1"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.3.2"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.0"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:2.3.6"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:3.2.2"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:3.2.1"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:3.2.6"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:3.2.4"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:3.1"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:3.2"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:3.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.111.8"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.115.7"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.115.34"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.115.48"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:11.1.115.54"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:google:android:4.1"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:4.0.4"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:4.0.3"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:4.0.2"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:4.0.1"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:google:android:4.2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.6.0.597"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.6.0.6090"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.7.0.1530"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.1.0.488"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.5.0.1060"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.5.0.880"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.2.0.2070"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.2.0.207"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.5.0.600"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.4.0.2540"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.3.0.3670"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.5.0.890"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.0.0.4080"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.4.0.2710"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.1.0.4880"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.1.0.485"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air:3.0.0.408"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.6.0.599"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.6.0.6090"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.7.0.1530"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.2.0.2070"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.3.0.3650"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.5.0.890"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.5.0.880"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.0.0.4080"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.5.0.600"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.1.0.488"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.4.0.2710"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.3.0.3690"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.4.0.2540"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:adobe_air_sdk:3.5.0.1060"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:flash_player:11.6.602.168</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.5.0.600</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.48</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.53.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.1.102.62</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.61</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.3.300.273</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.5</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.15</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:6.0.21.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.1.0.4880</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.270</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.5.0.880</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.5.502.110</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.4.402.265</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.275</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.67</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.28.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.31.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.25</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.1.115.54</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.262.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.1</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.61.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.223</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.20.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.19</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.5.502.149</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.4.0.2710</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.125.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.181.23</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.16</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.258</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.6.602.171</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.73.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.124.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.63</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.1.115.34</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.0.15.3</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.1.111.44</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.260.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.29</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.2.154.25</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.6.602.180</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.35.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:6.0.79</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.5.0.1060</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.5.0.890</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.66.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.48.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.20</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.106.17</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.3.300.270</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.3.300.265</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.125.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.92.8</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.68.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.1.102.55</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.2.0.207</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.34.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.42.0</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.3.0.3690</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.28</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.63</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.2</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.1.0.488</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.151.0</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.0.0.4080</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.2.156.12</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.52.14.1</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.18</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.68</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.0.22.87</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.155.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.18d60</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.112.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.102.64</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.2.152.32</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.5.502.135</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.70.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.152.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.1.111.8</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.261</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.7.700.169</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.69.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.5.502.146</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.181.34</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.19.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.2.154.13</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.67.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.0.12.10</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.235</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.4.0.2710</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.283.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.280</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.5.0.890</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.0.12.36</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.60.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.181.16</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.1.0.488</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.0.0.408</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.5.0.1060</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.236</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.2.157.51</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.6.0.597</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.2.153.1</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.1.115.7</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.1</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.6.0.6090</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.246.0</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.7.0.1530</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.0.32.18</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.2.152.33</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.1.111.50</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.3.0.3670</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.5.502.136</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.95.2</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.0.0.584</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.85.3</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.273</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.280</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.238</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.0.0.4080</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.0.1.153</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.228</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.2.0.2070</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.24.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.3.300.262</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.11</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.53.64</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.82.76</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.181.14</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.39.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.181.26</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.181.22</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.4.402.287</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.0.1.152</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.2.152.26</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.31</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.3.300.257</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.4.402.278</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.159.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.23</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.6.0.599</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.43</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.52.15</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.4.0.2540</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.4.0.2540</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.2.159.1</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.20</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.277.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.45.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.2.152</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.233</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.24.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.52.14</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.1.115.48</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.0.42.34</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.22.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.33.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.7</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.25</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.114.0</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.5.0.600</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.105.6</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.1.102.59</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.3.300.271</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.262</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.92.10</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:7.0.14.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.115.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.16</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.3.0.3650</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.1.102.63</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.6.602.167</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.7.0.1530</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.47.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.10</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.251</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.50</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.3.300.268</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.0.2.54</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.106.16</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.75</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air:3.1.0.485</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.2.0.2070</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.6.0.6090</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:11.2.202.243</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.0.45.2</vuln:product>
      <vuln:product>cpe:/a:adobe:adobe_air_sdk:3.5.0.880</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.3.183.51</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:10.1.95.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2728</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.240-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T12:27:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-14.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-14.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK &amp; Compiler before 3.7.0.1860 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3324, CVE-2013-3325, CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330, CVE-2013-3331, CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, and CVE-2013-3335.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2729">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2729</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.263-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T11:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2730">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2730</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.287-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T11:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2733.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2731">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2731</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.313-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T12:26:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2732">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2732</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.373-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T12:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2733">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2733</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.393-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T12:31:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2730.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2734">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2734</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.413-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T12:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2735">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2735</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.437-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T12:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2736">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2736</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.453-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T12:38:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2737">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.1:-:pro"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:10.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:11.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.6:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2:-</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:10.1.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3:-:pro</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:10.1.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.3.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.4.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:9.5.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:9.4.3:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2737</vuln:cve-id>
    <vuln:published-datetime>2013-05-16T07:45:31.477-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-16T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-16T12:38:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb13-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb13-15.html</vuln:reference>
    </vuln:references>
    <vuln:summary>A JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to obtain sensitive information via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2836">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.91"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.90"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.89"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.88"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.87"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.86"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.85"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.84"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.83"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.82"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.81"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.80"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.79"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.78"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.77"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.76"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.75"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.74"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.73"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.72"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.71"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.70"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.69"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.68"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.67"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.66"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.65"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.64"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.63"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.62"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.61"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.60"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.59"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.58"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.57"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.56"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.55"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.54"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.52"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.51"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.50"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.49"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.47"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.46"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.45"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.44"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.43"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.42"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.41"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.40"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.39"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.38"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.37"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.36"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.35"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.34"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.15"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.13"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.12"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.11"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.0"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.1"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.2"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.3"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.4"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.5"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.6"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.7"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.8"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.9"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.84</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.42</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.46</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.82</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.12</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.40</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.60</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.7</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.63</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.15</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.43</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.47</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.61</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.45</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.90</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.49</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.3</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.72</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.89</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.34</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.51</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.9</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.13</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.57</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.50</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.81</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.85</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.5</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.2</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.55</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.8</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.69</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.10</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.44</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.67</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.39</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.86</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.59</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.38</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.54</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.58</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.80</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.62</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.1</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.70</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.79</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.65</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.87</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.74</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.88</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.56</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.73</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.91</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.6</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.52</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.77</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.78</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.76</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.0</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.35</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.4</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.83</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.71</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.66</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.68</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.41</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.11</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.36</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.75</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.37</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2836</vuln:cve-id>
    <vuln:published-datetime>2013-05-22T09:29:55.893-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T10:52:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=241595" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=241595</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=236631" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=236631</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=232865" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=232865</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=232532" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=232532</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=232389" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=232389</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=231725" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=231725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=229402" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=229402</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=227390" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=227390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=226659" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=226659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=226090" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=226090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=226012" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=226012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=225979" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=225979</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=225403" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=225403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=224920" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=224920</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=223145" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=223145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=223125" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=223125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=223034" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=223034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=222770" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=222770</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=222754" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=222754</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=222036" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=222036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=196648" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=196648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=196575" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=196575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=196571" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=196571</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=181438" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=181438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=181375" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=181375</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=180920" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=180920</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=180058" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=180058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=179580" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=179580</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=178761" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=178761</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=178581" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=178581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=178269" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=178269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=178130" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=178130</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=177815" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=177815</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=176719" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=176719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=174920" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=174920</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=173672" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=173672</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=173397" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=173397</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=170715" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=170715</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=168050" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=168050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=162896" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=162896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://googlechromereleases.blogspot.com/2013/05/stable-channel-release.html" xml:lang="en">http://googlechromereleases.blogspot.com/2013/05/stable-channel-release.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Google Chrome before 27.0.1453.93 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2837">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.91"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.90"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.89"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.88"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.87"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.86"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.85"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.84"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.83"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.82"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.81"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.80"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.79"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.78"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.77"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.76"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.75"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.74"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.73"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.72"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.71"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.70"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.69"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.68"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.67"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.66"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.65"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.64"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.63"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.62"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.61"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.60"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.59"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.58"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.57"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.56"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.55"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.54"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.52"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.51"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.50"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.49"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.47"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.46"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.45"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.44"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.43"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.42"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.41"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.40"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.39"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.38"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.37"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.36"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.35"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.34"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.15"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.13"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.12"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.11"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.0"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.1"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.2"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.3"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.4"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.5"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.6"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.7"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.8"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.9"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.84</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.42</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.46</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.82</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.12</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.40</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.60</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.7</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.63</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.15</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.43</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.47</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.61</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.45</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.90</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.49</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.3</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.72</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.89</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.34</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.51</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.9</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.13</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.57</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.50</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.81</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.85</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.5</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.2</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.55</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.8</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.69</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.10</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.44</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.67</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.39</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.86</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.59</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.38</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.54</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.58</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.80</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.62</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.1</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.70</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.79</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.65</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.87</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.74</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.88</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.56</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.73</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.91</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.6</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.52</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.77</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.78</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.76</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.0</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.35</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.4</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.83</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.71</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.66</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.68</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.41</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.11</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.36</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.75</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.37</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2837</vuln:cve-id>
    <vuln:published-datetime>2013-05-22T09:29:55.977-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T11:20:27.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T11:19:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=235638" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=235638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://googlechromereleases.blogspot.com/2013/05/stable-channel-release.html" xml:lang="en">http://googlechromereleases.blogspot.com/2013/05/stable-channel-release.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2838">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.91"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.90"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.89"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.88"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.87"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.86"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.85"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.84"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.83"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.82"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.81"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.80"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.79"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.78"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.77"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.76"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.75"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.74"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.73"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.72"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.71"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.70"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.69"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.68"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.67"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.66"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.65"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.64"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.63"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.62"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.61"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.60"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.59"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.58"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.57"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.56"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.55"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.54"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.52"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.51"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.50"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.49"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.47"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.46"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.45"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.44"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.43"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.42"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.41"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.40"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.39"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.38"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.37"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.36"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.35"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.34"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.15"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.13"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.12"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.11"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.0"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.1"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.2"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.3"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.4"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.5"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.6"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.7"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.8"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.9"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.10"/>
        <cpe-lang:fact-ref name="cpe:/a:google:v8:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.84</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.42</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.46</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.82</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.12</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.40</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.60</vuln:product>
      <vuln:product>cpe:/a:google:v8:-</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.7</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.63</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.15</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.43</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.47</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.61</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.45</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.90</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.49</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.3</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.72</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.89</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.34</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.51</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.9</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.13</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.57</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.50</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.81</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.85</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.5</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.2</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.55</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.8</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.69</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.10</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.44</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.67</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.39</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.86</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.59</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.38</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.54</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.58</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.80</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.62</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.1</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.70</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.79</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.65</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.87</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.74</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.88</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.56</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.73</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.91</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.6</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.52</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.77</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.78</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.76</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.0</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.35</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.4</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.83</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.71</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.66</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.68</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.41</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.11</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.36</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.75</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.37</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2838</vuln:cve-id>
    <vuln:published-datetime>2013-05-22T09:29:55.987-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T11:14:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=235311" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=235311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://googlechromereleases.blogspot.com/2013/05/stable-channel-release.html" xml:lang="en">http://googlechromereleases.blogspot.com/2013/05/stable-channel-release.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Google V8, as used in Google Chrome before 27.0.1453.93, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2839">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.91"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.90"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.89"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.88"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.87"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.86"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.85"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.84"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.83"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.82"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.81"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.80"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.79"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.78"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.77"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.76"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.75"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.74"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.73"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.72"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.71"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.70"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.69"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.68"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.67"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.66"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.65"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.64"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.63"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.62"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.61"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.60"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.59"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.58"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.57"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.56"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.55"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.54"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.52"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.51"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.50"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.49"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.47"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.46"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.45"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.44"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.43"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.42"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.41"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.40"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.39"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.38"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.37"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.36"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.35"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.34"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.15"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.13"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.12"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.11"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.0"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.1"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.2"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.3"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.4"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.5"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.6"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.7"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.8"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.9"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.84</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.42</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.46</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.82</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.12</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.40</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.60</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.7</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.63</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.15</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.43</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.47</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.61</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.45</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.90</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.49</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.3</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.72</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.89</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.34</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.51</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.9</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.13</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.57</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.50</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.81</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.85</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.5</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.2</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.55</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.8</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.69</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.10</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.44</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.67</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.39</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.86</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.59</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.38</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.54</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.58</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.80</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.62</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.1</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.70</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.79</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.65</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.87</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.74</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.88</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.56</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.73</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.91</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.6</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.52</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.77</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.78</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.76</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.0</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.35</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.4</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.83</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.71</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.66</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.68</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.41</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.11</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.36</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.75</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.37</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2839</vuln:cve-id>
    <vuln:published-datetime>2013-05-22T09:29:55.997-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T11:19:49.077-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T11:18:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=230176" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=230176</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://googlechromereleases.blogspot.com/2013/05/stable-channel-release.html" xml:lang="en">http://googlechromereleases.blogspot.com/2013/05/stable-channel-release.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Google Chrome before 27.0.1453.93 does not properly perform a cast of an unspecified variable during handling of clipboard data, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2840">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.91"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.90"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.89"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.88"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.87"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.86"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.85"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.84"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.83"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.82"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.81"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.80"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.79"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.78"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.77"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.76"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.75"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.74"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.73"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.72"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.71"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.70"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.69"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.68"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.67"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.66"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.65"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.64"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.63"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.62"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.61"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.60"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.59"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.58"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.57"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.56"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.55"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.54"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.52"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.51"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.50"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.49"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.47"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.46"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.45"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.44"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.43"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.42"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.41"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.40"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.39"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.38"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.37"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.36"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.35"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.34"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.15"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.13"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.12"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.11"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.0"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.1"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.2"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.3"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.4"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.5"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.6"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.7"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.8"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.9"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.84</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.42</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.46</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.82</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.12</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.40</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.60</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.7</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.63</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.15</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.43</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.47</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.61</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.45</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.90</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.49</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.3</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.72</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.89</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.34</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.51</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.9</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.13</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.57</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.50</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.81</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.85</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.5</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.2</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.55</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.8</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.69</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.10</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.44</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.67</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.39</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.86</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.59</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.38</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.54</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.58</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.80</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.62</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.1</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.70</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.79</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.65</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.87</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.74</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.88</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.56</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.73</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.91</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.6</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.52</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.77</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.78</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.76</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.0</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.35</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.4</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.83</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.71</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.66</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.68</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.41</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.11</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.36</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.75</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.37</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2013-2840</vuln:cve-id>
    <vuln:published-datetime>2013-05-22T09:29:56.013-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-05-22T11:30:15.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2013-05-22T11:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://code.google.com/p/chromium/issues/detail?id=230117" xml:lang="en">https://code.google.com/p/chromium/issues/detail?id=230117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://googlechromereleases.blogspot.com/2013/05/stable-channel-release.html" xml:lang="en">http://googlechromereleases.blogspot.com/2013/05/stable-channel-release.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2013-2846.</vuln:summary>
  </entry>
  <entry id="CVE-2013-2841">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.91"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.90"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.89"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.88"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.87"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.86"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.85"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.84"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.83"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.82"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.81"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.80"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.79"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.78"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.77"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.76"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.75"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.74"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.73"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.72"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.71"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.70"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.69"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.68"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.67"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.66"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.65"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.64"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.63"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.62"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.61"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.60"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.59"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.58"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.57"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.56"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.55"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.54"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.52"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.51"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.50"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.49"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.47"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.46"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.45"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.44"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.43"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.42"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.41"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.40"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.39"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.38"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.37"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.36"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.35"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.34"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.15"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.13"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.12"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.11"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.0"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.1"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.2"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.3"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.4"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.5"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.6"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.7"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.8"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.9"/>
        <cpe-lang:fact-ref name="cpe:/a:google:chrome:27.0.1453.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.84</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.42</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.46</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.82</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.12</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.40</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.60</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.7</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.63</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.15</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.43</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.47</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.61</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.45</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.90</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.49</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.3</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.72</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.89</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.34</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.51</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.9</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.13</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.57</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.50</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.81</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.85</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.5</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.2</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.55</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.8</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.69</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.10</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.44</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.67</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.39</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.86</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.59</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.38</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.54</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.58</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.80</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.62</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.1</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.70</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.79</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.65</vuln:product>
      <vuln:product>cpe:/a:google:chrome:27.0.1453.87</vuln: