<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" nvd_xml_version="2.0" pub_date="2009-11-22T12:05:00" xsi:schemaLocation="http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
    <entry id="CVE-1999-1395">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.1b" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.2" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.3" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.4" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.4.1" />
                <cpe-lang:fact-ref name="cpe:/a:dec:dec_openvms:5.4.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:dec:dec_openvms:5.4</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.1.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.1.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.4.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.0</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.2.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.3</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.4.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.1b</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.0.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.0.2</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.3.1</vuln:product>
            <vuln:product>cpe:/a:dec:dec_openvms:5.3.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-1395</vuln:cve-id>
        <vuln:published-datetime>1992-11-17T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T00:02:35.750-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-92.16.VMS.Monitor.vulnerability">CA-92.16</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cert.org/advisories/CA-1992-18.html">CA-1992-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/51">51</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.iss.net/security_center/static/7136.php">vms-monitor-gain-privileges(7136)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59332">59332</vuln:reference>
        </vuln:references>
        <vuln:summary>Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.</vuln:summary>
    </entry>
    <entry id="CVE-1999-0593">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-1999-0593</vuln:cve-id>
        <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T00:01:02.017-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/1291">nt-shutdown-without-logon(1291)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true">http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://technet.microsoft.com/en-us/library/cc722469.aspx">http://technet.microsoft.com/en-us/library/cc722469.aspx</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/59333">59333</vuln:reference>
        </vuln:references>
        <vuln:summary>The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0498">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:intersystems:cache_database:5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0498</vuln:cve-id>
        <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-22T00:20:53.703-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-94" />
        <vuln:summary>Cach�Ã�© Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.</vuln:summary>
    </entry>
    <entry id="CVE-2003-0497">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database:5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:intersystems:cache_database:5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2003-0497</vuln:cve-id>
        <vuln:published-datetime>2003-08-07T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-22T00:20:47.517-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.2</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:summary>Cach�Ã�© Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0077">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::woody" />
                <cpe-lang:fact-ref name="cpe:/o:gentoo:linux" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation" />
                <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.10" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:gentoo:linux</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.10</vuln:product>
            <vuln:product>cpe:/o:debian:debian_linux:3.0::woody</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
            <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0077</vuln:cve-id>
        <vuln:published-datetime>2005-05-02T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-13T00:35:29.127-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-06-02T22:05:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/19068">dbi-library-file-overwrite(19068)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-072.html">RHSA-2005:072</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml">GLSA-200501-38</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-658">DSA-658</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110667936707597&amp;w=2">20050125 [USN-70-1] Perl DBI module vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/12360">12360</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/426530/30/6600/threaded">FLSA-2006:178989</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:030">MDKSA-2005:030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1013007">1013007</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14050">14050</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14015">14015</vuln:reference>
        </vuln:references>
        <vuln:summary>The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.</vuln:summary>
    </entry>
    <entry id="CVE-2005-0106">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-0106</vuln:cve-id>
        <vuln:published-datetime>2005-05-03T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-13T00:39:05.670-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-05-12T15:05:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-113-1">USN-113-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/13471">13471</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:023">MDKSA-2006:023</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18639">18639</vuln:reference>
        </vuln:references>
        <vuln:summary>SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.</vuln:summary>
    </entry>
    <entry id="CVE-2005-2088">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.29" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.30" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.31" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.33" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.49" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.50" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.51" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.52" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.53" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.54" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.29</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.49</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.30</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.50</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.51</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.31</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.52</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.53</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.54</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.33</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-2088</vuln:cve-id>
        <vuln:published-datetime>2005-07-05T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-08T00:44:39.920-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-07-05T14:17:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:840" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:840" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1629" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1629" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1526" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1526" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1237" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1237" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00612828">SSRT051128</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-160-2">USN-160-2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/15647">15647</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/14106">14106</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securiteam.com/securityreviews/5GP0220G0U.html">http://www.securiteam.com/securityreviews/5GP0220G0U.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-582.html">RHSA-2005:582</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/1018">ADV-2006-1018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/2659">ADV-2005-2659</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/2140">ADV-2005-2140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-805">DSA-805</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-803">DSA-803</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.apache.org/dist/httpd/CHANGES_2.0">http://www.apache.org/dist/httpd/CHANGES_2.0</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.apache.org/dist/httpd/CHANGES_1.3">http://www.apache.org/dist/httpd/CHANGES_1.3</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK16139&amp;apar=only">PK16139</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK13959&amp;apar=only">PK13959</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1">102197</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2005&amp;m=slackware-security.600000">SSA:2005-310-04</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1014323">1014323</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19317">19317</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19185">19185</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19073">19073</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19072">19072</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17813">17813</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17487">17487</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17319">17319</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/14530">14530</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://seclists.org/lists/bugtraq/2005/Jun/0025.html">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc2.theaimsgroup.com/?l=apache-httpd-announce&amp;m=112931556417329&amp;w=3">[apache-httpd-announce] 20051014 Apache HTTP Server 2.0.55 Released</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html">TSLSA-2005-0059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=302847">APPLE-SA-2005-11-29</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://secure-support.novell.com/KanisaPlatform/Publishing/741/3222109_f.SAL_Public.html">https://secure-support.novell.com/KanisaPlatform/Publishing/741/3222109_f.SAL_Public.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_46_apache.html">SUSE-SA:2005:046</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:130">MDKSA-2005:130</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4680">ADV-2006-4680</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/604">604</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23074">23074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:130">MDKSA-2005:130</vuln:reference>
        </vuln:references>
        <vuln:summary>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</vuln:summary>
    </entry>
    <entry id="CVE-2005-1921">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc1" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc2" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc3" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc4" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc5" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc6" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.0rc7" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.3.0rc1" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.3.0rc2" />
                <cpe-lang:fact-ref name="cpe:/a:pear:xml_rpc:1.3.0rc3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:pear:xml_rpc:1.0.4</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc7</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.0.2</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.0.3</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc3</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.3.0rc1</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc4</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.3.0rc2</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc5</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.3.0rc3</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc6</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.2</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc2</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.1</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.2.0rc1</vuln:product>
            <vuln:product>cpe:/a:pear:xml_rpc:1.1.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-1921</vuln:cve-id>
        <vuln:published-datetime>2005-07-05T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-07T00:40:39.670-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-07-05T11:58:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:350" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:350" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:109">MDKSA-2005:109</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gulftech.org/?node=research&amp;article_id=00087-07012005">http://www.gulftech.org/?node=research&amp;article_id=00087-07012005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://pear.php.net/package/XML_RPC/download/1.3.1">http://pear.php.net/package/XML_RPC/download/1.3.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112008638320145&amp;w=2">20050629 Advisory 02/2005: Remote code execution in Serendipity</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/419064/100/0/threaded">HPSBTU02083</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.hardened-php.net/advisory-022005.php">http://www.hardened-php.net/advisory-022005.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/14088">14088</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/419064/100/0/threaded">HPSBTU02083</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-564.html">RHSA-2005:564</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_49_php.html">SUSE-SA:2005:049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_41_php_pear.html">SUSE-SA:2005:041</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/2827">ADV-2005-2827</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt">http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-789">DSA-789</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-747">DSA-747</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-746">DSA-746</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-745">DSA-745</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ampache.org/announce/3_3_1_2.php">http://www.ampache.org/announce/3_3_1_2.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/shownotes.php?release_id=338803">http://sourceforge.net/project/shownotes.php?release_id=338803</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/project/showfiles.php?group_id=87163">http://sourceforge.net/project/showfiles.php?group_id=87163</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015336">1015336</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200507-07.xml">GLSA-200507-07</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200507-06.xml">GLSA-200507-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200507-01.xml">GLSA-200507-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18003">18003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17674">17674</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17440">17440</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/16693">16693</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/16339">16339</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/16001">16001</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15957">15957</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15947">15947</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15944">15944</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15922">15922</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15917">15917</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15916">15916</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15904">15904</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15903">15903</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15895">15895</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15884">15884</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15883">15883</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15872">15872</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15861">15861</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15855">15855</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15852">15852</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/15810">15810</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2">SUSE-SA:2005:051</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112015336720867&amp;w=2">20050629 [DRUPAL-SA-2005-003] Drupal 4.6.2 / 4.5.4 fixes critical XML-RPC issue</vuln:reference>
        </vuln:references>
        <vuln:summary>Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.</vuln:summary>
    </entry>
    <entry id="CVE-2005-1689">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3.5" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.3.6" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.4" />
                <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.4.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3.2</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3.1</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.4.1</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3.3</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3.4</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3.5</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.3.6</vuln:product>
            <vuln:product>cpe:/a:mit:kerberos:5-1.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-1689</vuln:cve-id>
        <vuln:published-datetime>2005-07-18T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-29T00:38:07.547-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-07-18T09:53:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/623332">VU#623332</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200507-11.xml">GLSA-200507-11</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-757">DSA-757</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/21055">kerberos-kdc-krb5recvauth-execute-code(21055)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-224-1">USN-224-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TURBO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.turbolinux.com/security/2005/TLSA-2005-78.txt">TLSA-2005-78</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2005/0036">2005-0036</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/14239">14239</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-567.html">RHSA-2005:567</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-562.html">RHSA-2005:562</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_17_sr.html">SUSE-SR:2005:017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3776">ADV-2006-3776</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/1066">ADV-2005-1066</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txt">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101810-1">101810</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1014461">1014461</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22090">22090</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17899">17899</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17135">17135</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/16041">16041</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112119974704542&amp;w=2">20050712 MITKRB5-SA-2005-003: double-free in krb5_recvauth</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000993">CLA-2005:993</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.asc">20050703-01-U</vuln:reference>
        </vuln:references>
        <vuln:summary>Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.</vuln:summary>
    </entry>
    <entry id="CVE-2005-2491">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:pcre:pcre:5.0" />
                <cpe-lang:fact-ref name="cpe:/a:pcre:pcre:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:pcre:pcre:6.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:pcre:pcre:5.0</vuln:product>
            <vuln:product>cpe:/a:pcre:pcre:6.0</vuln:product>
            <vuln:product>cpe:/a:pcre:pcre:6.1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-2491</vuln:cve-id>
        <vuln:published-datetime>2005-08-23T00:00:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-01T00:46:24.170-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-08-23T10:18:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:735" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:735" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1659" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1659" />
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1496" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1496" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1014744">1014744</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/14620">14620</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/15647">15647</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/427046/100/0/threaded">FLSA:168516</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2006-0197.html">RHSA-2006:0197</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-761.html">RHSA-2005:761</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-358.html">RHSA-2005:358</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/release_4_4_1.php">http://www.php.net/release_4_4_1.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_52_apache2.html">SUSE-SA:2005:052</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_49_php.html">SUSE-SA:2005:049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_48_pcre.html">SUSE-SA:2005:048</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200509-19.xml">GLSA-200509-19</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200509-12.xml">GLSA-200509-12</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200509-02.xml">GLSA-200509-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200508-17.xml">GLSA-200509-08</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4502">ADV-2006-4502</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4320">ADV-2006-4320</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/2659">ADV-2005-2659</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/1511">ADV-2005-1511</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ethereal.com/appnotes/enpa-sa-00021.html">http://www.ethereal.com/appnotes/enpa-sa-00021.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-821">DSA-821</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-819">DSA-819</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-817">DSA-817</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2005/dsa-800">DSA-800</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-159.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-159.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/604">604</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22875">22875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22691">22691</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21522">21522</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19532">19532</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19193">19193</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19072">19072</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17813">17813</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17252">17252</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/16679">16679</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/16502">16502</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112606064317223&amp;w=2">OpenPKG-SA-2005.018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2">SUSE-SA:2005:051</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html">TSLSA-2005-0059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522">SSRT061238</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=302847">APPLE-SA-2005-11-29</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U">20060401-01-U</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SCO</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txt">SCOSA-2006.10</vuln:reference>
        </vuln:references>
        <vuln:summary>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</vuln:summary>
    </entry>
    <entry id="CVE-2005-3962">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.8.6" />
                <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.9.2" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:larry_wall:perl:5.8.6</vuln:product>
            <vuln:product>cpe:/a:larry_wall:perl:5.9.2</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-3962</vuln:cve-id>
        <vuln:published-datetime>2005-12-01T12:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-08T00:51:15.017-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-12-01T12:21:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:1074" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1074" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/948385">VU#948385</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA06-333A.html">TA06-333A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.dyadsecurity.com/perl-0002.html">http://www.dyadsecurity.com/perl-0002.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113342788118630&amp;w=2">20051201 Perl format string integer wrap vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-legacy-announce/2006-February/msg00008.html">FLSA-2006:176731</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-222-1">USN-222-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2005/0070">TSLSA-2005-0070</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/15629">15629</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">HPSBTU02125</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">HPSBTU02125</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/418333/100/0/threaded">20051201 Perl format string integer wrap vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-881.html">RHSA-2005:881</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2005-880.html">RHSA-2005:880</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22255">22255</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/21345">21345</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.org/security/OpenPKG-SA-2005.025-perl.html">OpenPKG-SA-2005.025</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENBSD</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openbsd.org/errata37.html#perl">[3.7] 20060105 007: SECURITY FIX: January 5, 2006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_71_perl.html">SUSE-SA:2005:071</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200512-01.xml">GLSA-200512-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0771">ADV-2006-0771</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/2688">ADV-2005-2688</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-943">DSA-943</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102192-1">102192</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19041">19041</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18517">18517</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18413">18413</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18295">18295</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18187">18187</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18183">18183</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18075">18075</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17993">17993</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17952">17952</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17941">17941</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17844">17844</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17802">17802</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17762">17762</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113342788118630&amp;w=2">20051201 Perl format string integer wrap vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:225">MDKSA-2005:225</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONECTIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056">CLSA-2006:1056</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U">20060101-01-U</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/001_perl.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/001_perl.patch</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/007_perl.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/007_perl.patch</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">HPSBTU02125</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2005_29_sr.html">SUSE-SR:2005:029</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRAKE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:225">MDKSA-2005:225</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ipcop.org/index.php?name=News&amp;file=article&amp;sid=41">http://www.ipcop.org/index.php?name=News&amp;file=article&amp;sid=41</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4750">ADV-2006-4750</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/2613">ADV-2006-2613</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31208">31208</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23155">23155</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/20894">20894</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html">APPLE-SA-2006-11-28</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=304829">http://docs.info.apple.com/article.html?artnum=304829</vuln:reference>
        </vuln:references>
        <vuln:summary>Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.</vuln:summary>
    </entry>
    <entry id="CVE-2005-4209">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:alt-n:mdaemon:8.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:alt-n:worldclient:8.1.3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:alt-n:worldclient:8.1.3</vuln:product>
            <vuln:product>cpe:/a:alt-n:mdaemon:8.1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-4209</vuln:cve-id>
        <vuln:published-datetime>2005-12-13T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T00:54:01.500-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.1</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-12-13T10:36:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/23551">mdaemon-worldclient-subject-dos(23551)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/15815">15815</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ipomonis.com/advisories/mdaemon.zip">http://www.ipomonis.com/advisories/mdaemon.zip</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17990">17990</vuln:reference>
        </vuln:references>
        <vuln:summary>WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability.</vuln:summary>
    </entry>
    <entry id="CVE-2005-3352">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.10" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.11" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.11::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.12" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.12::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.13" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.13::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.14" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.14::mac_os" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.14::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.15" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.15::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.16" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.16::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.17" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.17::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.18" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.18::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.19" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.19::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.20" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.20::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.22" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.22::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.23" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.23::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.24" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.24::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.25" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.25::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.26" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.26::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.27" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.28" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.29" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.30" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.31" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.5" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.6" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.7" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.7::dev" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.8" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.9" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28:beta" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28:beta:win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32:beta:win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.34:beta:win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.49" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.50" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.51" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.52" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.53" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.54" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.55" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:apache:mod_imap" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:2.0.32:beta:win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.17::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.23::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.55</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.18</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.17</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.18::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.14::mac_os</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.19</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.14</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.25::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.19::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.13</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.16</vuln:product>
            <vuln:product>cpe:/a:apache:mod_imap</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.15</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.10</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.12</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.50</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.11</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.51</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.52</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.53</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.54</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.9</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.15::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.34:beta:win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.13::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.14::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.49</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.24::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.16::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28:beta:win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.9</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.8</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.30</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.7</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.6</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.11::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.31</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.7::dev</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.26::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.27</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.26</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.25</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.24</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28:beta</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.29</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.28</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.20::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.22::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.12::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.23</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.22</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.20</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-3352</vuln:cve-id>
        <vuln:published-datetime>2005-12-13T15:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-30T00:41:31.233-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2005-12-14T10:33:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA08-150A.html">TA08-150A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015344">1015344</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:007">MDKSA-2006:007</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/usn/usn-241-1">USN-241-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2005/0074/">TSLSA-2005-0074</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/15834">15834</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450321/100/0/threaded">SSRT061265</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/425399/100/0/threaded">FLSA-2006:175406</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2006-0158.html">RHSA-2006:0158</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00060.html">FEDORA-2006-052</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.org/security/OpenPKG-SA-2005.029-apache.txt">OpenPKG-SA-2005.029</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200602-03.xml">GLSA-200602-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2005/2870">ADV-2005-2870</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK16139&amp;apar=only">PK16139</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19012">19012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18743">18743</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18585">18585</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18526">18526</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18517">18517</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18429">18429</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18340">18340</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18339">18339</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18333">18333</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18008">18008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/17319">17319</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2006-0159.html">RHSA-2006:0159</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html">SUSE-SR:2006:004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://issues.apache.org/bugzilla/show_bug.cgi?id=37874">http://issues.apache.org/bugzilla/show_bug.cgi?id=37874</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U">20060101-01-U</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450321/100/0/threaded">SSRT061265</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450315/100/0/threaded">SSRT061269</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_43_apache.html">SUSE-SA:2006:043</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1697">ADV-2008-1697</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1246/references">ADV-2008-1246</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4868">ADV-2006-4868</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4300">ADV-2006-4300</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4015">ADV-2006-4015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3995">ADV-2006-3995</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/2423">ADV-2006-2423</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1167">DSA-1167</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK25355&amp;apar=only">PK25355</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1">102663</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1">102662</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.685483">SSA:2006-129-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.470158">SSA:2006-130-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30430">30430</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29849">29849</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29420">29420</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25239">25239</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23260">23260</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22669">22669</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22388">22388</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22368">22368</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22140">22140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21744">21744</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/20670">20670</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/20046">20046</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2006-0692.html">RHSA-2006:0692</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html">SUSE-SR:2007:011</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html">APPLE-SA-2008-05-28</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449">SSRT071293</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.</vuln:summary>
    </entry>
    <entry id="CVE-2005-4265">
        <vuln:cve-id>CVE-2005-4265</vuln:cve-id>
        <vuln:published-datetime>2005-12-15T06:03:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T00:54:22.077-04:00</vuln:last-modified-datetime>
        <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4209.  Reason: This candidate is a duplicate of CVE-2005-4209.  Notes: All CVE users should reference CVE-2005-4209 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
    </entry>
    <entry id="CVE-2005-4667">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:info-zip:unzip:5.2" />
                <cpe-lang:fact-ref name="cpe:/a:info-zip:unzip:5.3" />
                <cpe-lang:fact-ref name="cpe:/a:info-zip:unzip:5.31" />
                <cpe-lang:fact-ref name="cpe:/a:info-zip:unzip:5.32" />
                <cpe-lang:fact-ref name="cpe:/a:info-zip:unzip:5.40" />
                <cpe-lang:fact-ref name="cpe:/a:info-zip:unzip:5.41" />
                <cpe-lang:fact-ref name="cpe:/a:info-zip:unzip:5.42" />
                <cpe-lang:fact-ref name="cpe:/a:info-zip:unzip:5.50" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:info-zip:unzip:5.31</vuln:product>
            <vuln:product>cpe:/a:info-zip:unzip:5.42</vuln:product>
            <vuln:product>cpe:/a:info-zip:unzip:5.50</vuln:product>
            <vuln:product>cpe:/a:info-zip:unzip:5.41</vuln:product>
            <vuln:product>cpe:/a:info-zip:unzip:5.40</vuln:product>
            <vuln:product>cpe:/a:info-zip:unzip:5.3</vuln:product>
            <vuln:product>cpe:/a:info-zip:unzip:5.2</vuln:product>
            <vuln:product>cpe:/a:info-zip:unzip:5.32</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-4667</vuln:cve-id>
        <vuln:published-datetime>2005-12-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-12T00:52:35.563-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>3.7</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-26T09:12:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-248-2">USN-248-2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-248-1">USN-248-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2006/0006">2006-0006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/430300/100/0/threaded">FLSA:180159</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1012">DSA-1012</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/15968">15968</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0203.html">RHSA-2007:0203</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22400">22400</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25098">25098</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0930.html">20051219 Unzip *ALL* verisons ;))</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:050">MDKSA-2006:050</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument.  NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.</vuln:summary>
    </entry>
    <entry id="CVE-2005-4639">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-4639</vuln:cve-id>
        <vuln:published-datetime>2005-12-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-12T00:51:24.483-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-06-06T08:16:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1">USN-244-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16142">16142</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0035">ADV-2006-0035</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18527">18527</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18216">18216</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/43323">linux-kernel-cadriver-bo(43323)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in the CA-driver (dst_ca.c) for TwinHan DST Frontend/Card in Linux kernel 2.6.12 and other versions before 2.6.15 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by "reading more than 8 bytes into an 8 byte long array".</vuln:summary>
    </entry>
    <entry id="CVE-2005-4636">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice:1.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice:1.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice:1.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice:1.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice:1.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice:1.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openoffice:openoffice:1.0.1</vuln:product>
            <vuln:product>cpe:/a:openoffice:openoffice:1.0.2</vuln:product>
            <vuln:product>cpe:/a:openoffice:openoffice:1.1.2</vuln:product>
            <vuln:product>cpe:/a:openoffice:openoffice:1.1.3</vuln:product>
            <vuln:product>cpe:/a:openoffice:openoffice:1.1.0</vuln:product>
            <vuln:product>cpe:/a:openoffice:openoffice:1.1.1</vuln:product>
            <vuln:product>cpe:/a:openoffice:openoffice:2.0</vuln:product>
            <vuln:product>cpe:/a:openoffice:openoffice:1.1.4</vuln:product>
            <vuln:product>cpe:/a:openoffice:openoffice:1.1.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-4636</vuln:cve-id>
        <vuln:published-datetime>2005-12-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-12T00:51:24.170-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-12T22:47:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1015419">1015419</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://qa.openoffice.org/issues/show_bug.cgi?id=53491">http://qa.openoffice.org/issues/show_bug.cgi?id=53491</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:033">MDKSA-2006:033</vuln:reference>
        </vuln:references>
        <vuln:summary>OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, does not prevent the user from clicking the WWW-browser button in the Hyperlink dialog, which makes it easier for attackers to trick the user into bypassing intended security settings.</vuln:summary>
    </entry>
    <entry id="CVE-2005-4618">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0:test9" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6_test9_cvs" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.6:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6_test9_cvs</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test10</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.7:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.10:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.1:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test7</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test6</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.8:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test9</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.0:test8</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc5</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc1</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-4618</vuln:cve-id>
        <vuln:published-datetime>2005-12-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-12T00:51:20.547-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>3.6</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-06-05T14:58:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16141">16141</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/0035">ADV-2006-0035</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1018">DSA-1018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1017">DSA-1017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19374">19374</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19369">19369</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18527">18527</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18216">18216</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1">USN-244-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8febdd85adaa41fa1fc1cb31286210fc2cd3ed0c">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8febdd85adaa41fa1fc1cb31286210fc2cd3ed0c</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in sysctl in the Linux Kernel 2.6 before 2.6.15 allows local users to corrupt user memory and possibly cause a denial of service via a long string, which causes sysctl to write a zero byte outside the buffer.  NOTE: since the sysctl is called from a userland program that provides the argument, this might not be a vulnerability, unless a legitimate user-assisted or setuid scenario can be identified.</vuln:summary>
    </entry>
    <entry id="CVE-2005-4605">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc2" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc3" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc4" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc1" />
                <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc3" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc1</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc4</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc3</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc2</vuln:product>
            <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-4605</vuln:cve-id>
        <vuln:published-datetime>2005-12-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-12T00:51:19.360-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>2.1</cvss:score>
                <cvss:access-vector>LOCAL</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-03T12:49:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8b90db0df7187a01fb7177f1f812123138f562cf">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8b90db0df7187a01fb7177f1f812123138f562cf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113535380422339&amp;w=2">20051223 linux procfs vulnerablity</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://linux.bkbits.net:8080/linux-2.6/gnupatch@43b562ae6hJGLWZA4TNf2k-RzXnVlQ">http://linux.bkbits.net:8080/linux-2.6/gnupatch@43b562ae6hJGLWZA4TNf2k-RzXnVlQ</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://linux.bkbits.net:8080/linux-2.6/cset@43b562ae6hJGLWZA4TNf2k-RzXnVlQ">http://linux.bkbits.net:8080/linux-2.6/cset@43b562ae6hJGLWZA4TNf2k-RzXnVlQ</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/23811">linux-procfs-information-disclosure(23811)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1">USN-244-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16284">16284</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/427981/100/0/threaded">FLSA:157459-4</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2006-0101.html">RHSA-2006:0101</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00014.html">http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00014.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_06_kernel.html">SUSE-SA:2006:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1017">DSA-1017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19374">19374</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19038">19038</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18788">18788</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18527">18527</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18510">18510</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18351">18351</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18216">18216</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html">SUSE-SA:2006:012</vuln:reference>
        </vuln:references>
        <vuln:summary>The procfs code (proc_misc.c) in Linux 2.6.14.3 and other versions before 2.6.15 allows attackers to read sensitive kernel memory via unspecified vectors in which a signed value is added to an unsigned value.</vuln:summary>
    </entry>
    <entry id="CVE-2005-4604">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:jean-jacques_sarton:mtink:1.0.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:jean-jacques_sarton:mtink:1.0.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-4604</vuln:cve-id>
        <vuln:published-datetime>2005-12-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-12T00:51:19.110-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-03T08:00:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16095">16095</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18287">18287</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18249">18249</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2005:239">MDKSA-2005:239</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in MTink in the printer-filters-utils package allows local users to execute arbitrary code via a long HOME environment variable.</vuln:summary>
    </entry>
    <entry id="CVE-2005-4601">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.2.4.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:imagemagick:imagemagick:6.2.4.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2005-4601</vuln:cve-id>
        <vuln:published-datetime>2005-12-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-12T00:51:18.797-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>7.5</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-01-03T07:51:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/16093">16093</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18261">18261</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345238">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345238</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-389">https://issues.rpath.com/browse/RPL-389</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/23927">imagemagick-filename-command-injection(23927)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-246-1">USN-246-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/452718/100/100/threaded">20061127 rPSA-2006-0218-1 ImageMagick</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/22121">22121</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_06_sr.html">SUSE-SR:2006:006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:024">MDKSA-2006:024</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0412">ADV-2008-0412</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-957">DSA-957</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1">231321</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.341682">SSA:2006-045-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28800">28800</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23090">23090</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19408">19408</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/19183">19183</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18871">18871</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18631">18631</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/18607">18607</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2006-0178.html">RHSA-2006:0178</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc">20060301-01-U</vuln:reference>
        </vuln:references>
        <vuln:summary>The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.</vuln:summary>
    </entry>
    <entry id="CVE-2006-3918">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.11::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.12" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.12::win32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.17" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.18" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.19" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.20" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.22" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.57" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:http_server:6.0" />
                <cpe-lang:fact-ref name="cpe:/a:ibm:http_server:6.1" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ibm:http_server:6.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.18</vuln:product>
            <vuln:product>cpe:/a:ibm:http_server:6.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.17</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.57</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.19</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.12</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.11::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.12::win32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.22</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.20</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-3918</vuln:cve-id>
        <vuln:published-datetime>2006-07-27T20:04:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T01:17:06.610-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics upgraded-from-version="1.0">
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-07-31T15:50:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/2964">ADV-2006-2964</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/2963">ADV-2006-2963</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21174">21174</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21172">21172</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2006-0619.html">RHSA-2006:0619</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3264">ADV-2006-3264</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg24013080">PK27875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg1PK24631">PK24631</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://svn.apache.org/viewvc?view=rev&amp;revision=394965">http://svn.apache.org/viewvc?view=rev&amp;revision=394965</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1016569">1016569</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21478">21478</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21399">21399</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2006-0618.html">RHSA-2006:0618</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/bugtraq/2006-07/0425.html">20060724 Write-up by Amit Klein: "Forging HTTP request headers with Flash"</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/bugtraq/2006-05/0151.html">20060508 Unfiltered Header Injection in Apache 1.3.34/2.0.57/2.2.1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-575-1">USN-575-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/19661">19661</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_51_apache.html">SUSE-SA:2006:051</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/5089">ADV-2006-5089</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4207">ADV-2006-4207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1167">DSA-1167</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-194.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-194.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/1294">1294</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29640">29640</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28749">28749</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22523">22523</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22317">22317</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22140">22140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21986">21986</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21848">21848</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21744">21744</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21598">21598</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2006-0692.html">RHSA-2006:0692</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENBSD</vuln:source>
            <vuln:reference xml:lang="en" href="http://openbsd.org/errata.html#httpd2">[3.9] 012: SECURITY FIX: October 7, 2006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html">SUSE-SA:2008:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://kb.vmware.com/KanisaPlatform/Publishing/466/5915871_f.SAL_Public.html">http://kb.vmware.com/KanisaPlatform/Publishing/466/5915871_f.SAL_Public.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P">20060801-01-P</vuln:reference>
        </vuln:references>
        <vuln:summary>http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.</vuln:summary>
    </entry>
    <entry id="CVE-2006-3747">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.28" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.29" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.30" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.31" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.33" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.5" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.6" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.7" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.7::dev" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.8" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3.9" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.49" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.50" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.51" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.52" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.53" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.54" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.55" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.56" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.57" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.58" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.04" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10" />
                <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.06_lts" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.04</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.55</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.56</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.57</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.58</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.9</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.8</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.7</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.30</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.6</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.50</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.51</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.31</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.52</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.7::dev</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.53</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.33</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.54</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
            <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.06_lts</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.29</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:1.3.28</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.49</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-3747</vuln:cve-id>
        <vuln:published-datetime>2006-07-28T14:02:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-27T00:47:03.577-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.6</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-07-31T16:54:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-189" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/395412">VU#395412</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA08-150A.html">TA08-150A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1132">DSA-1132</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1131">DSA-1131</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.apache.org/dist/httpd/Announcement2.0.html">http://www.apache.org/dist/httpd/Announcement2.0.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-538">https://issues.rpath.com/browse/RPL-538</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/28063">apache-modrewrite-offbyone-bo(28063)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-328-1">USN-328-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/19204">19204</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450321/100/0/threaded">HPSBUX02164</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/443870/100/0/threaded">20060820 POC &amp; exploit for Apache mod_rewrite off-by-one</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/441526/100/200/threaded">20060728 rPSA-2006-0139-1 httpd mod_ssl</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/441487/100/0/threaded">20060728 Apache mod_rewrite Buffer Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/441485/100/0/threaded">20060728 [Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/27588">27588</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.015-apache.html">OpenPKG-SA-2006.015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_43_apache.html">SUSE-SA:2006:043</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4015">ADV-2006-4015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3995">ADV-2006-3995</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3884">ADV-2006-3884</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3282">ADV-2006-3282</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3264">ADV-2006-3264</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3017">ADV-2006-3017</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg24013080">PK27875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg1PK29156">PK29156</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg1PK29154">PK29154</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://svn.apache.org/viewvc?view=rev&amp;revision=426144">http://svn.apache.org/viewvc?view=rev&amp;revision=426144</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1">102663</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1">102662</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1016601">1016601</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200608-01.xml">GLSA-200608-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22388">22388</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22368">22368</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22262">22262</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21509">21509</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21478">21478</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21315">21315</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21313">21313</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21307">21307</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21284">21284</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21273">21273</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21266">21266</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21247">21247</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21245">21245</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21241">21241</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21197">21197</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048271.html">20060728 [Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048267.html">20060728 Apache 1.3.29/2.X mod_rewrite Buffer Overflow Vulnerability CVE-2006-3747</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://kbase.redhat.com/faq/FAQ_68_8653.shtm">http://kbase.redhat.com/faq/FAQ_68_8653.shtm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:133">MDKSA-2006:133</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450321/100/0/threaded">HPSBUX02164</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:133">MDKSA-2006:133</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1697">ADV-2008-1697</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1246/references">ADV-2008-1246</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/2783">ADV-2007-2783</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4868">ADV-2006-4868</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4300">ADV-2006-4300</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4207">ADV-2006-4207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg27007951">http://www-1.ibm.com/support/docview.wss?uid=swg27007951</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/1312">1312</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30430">30430</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29849">29849</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29420">29420</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26329">26329</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23260">23260</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23028">23028</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22523">22523</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21346">21346</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://lwn.net/Alerts/194228/">2006-0044</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html">APPLE-SA-2008-05-28</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449">HPSBMA02328</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771">SSRT061275</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
        </vuln:references>
        <vuln:summary>Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.</vuln:summary>
    </entry>
    <entry id="CVE-2006-4339">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7a" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7b" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7c" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7d" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7e" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7f" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7g" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7h" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7i" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7j" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8a" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.8b" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.7" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6g" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6f" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6i" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6h" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6c" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6e" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6d" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6k" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6j" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6l" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6b" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6a:beta3" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6:beta3" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5a:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.3a" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.4" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.5:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.3" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.2b" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.1c" />
                <cpe-lang:fact-ref name="cpe:/a:openssl:openssl:0.9.6m" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openssl:openssl:0.9.3</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.4</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.8</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6a</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6b</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.1c</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.8b</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6c</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.8a</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6d</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6a:beta1</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6e</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6f</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6a:beta3</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6g</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6a:beta2</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6h</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6:beta1</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6:beta2</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6:beta3</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7j</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7i</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7h</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7g</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7f</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7e</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7d</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7c</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7b</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5:beta2</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.7a</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.2b</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5:beta1</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5a</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.3a</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6m</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6k</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5a:beta2</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.5a:beta1</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6l</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6i</vuln:product>
            <vuln:product>cpe:/a:openssl:openssl:0.9.6j</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-4339</vuln:cve-id>
        <vuln:published-datetime>2006-09-05T13:04:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-21T01:09:20.297-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>5.1</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-09-05T13:17:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-310" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/845620">VU#845620</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA06-333A.html">TA06-333A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us.debian.org/security/2006/dsa-1173">DSA-1173</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-339-1">USN-339-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/19849">19849</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openssl.org/news/secadv_20060905.txt">http://www.openssl.org/news/secadv_20060905.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3453">ADV-2006-3453</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2006/dsa-1174">DSA-1174</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21709">21709</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-616">https://issues.rpath.com/browse/RPL-616</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/28755">openssl-rsa-security-bypass(28755)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445822/100/0/threaded">20060912 ERRATA: [ GLSA 200609-05 ] OpenSSL, AMD64 x86 emulation base libraries: RSA signature forgery</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/445231/100/0/threaded">20060905 rPSA-2006-0163-1 openssl openssl-scripts</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0629.html">RHSA-2008:0629</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2006-0661.html">RHSA-2006:0661</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.osvdb.org/28549">28549</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.opera.com/support/search/supsearch.dml?index=845">http://www.opera.com/support/search/supsearch.dml?index=845</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENBSD</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openbsd.org/errata.html">[3.9] 20060908 011: SECURITY FIX: September 8, 2006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_55_ssl.html">SUSE-SA:2006:055</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/">http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:161">MDKSA-2006:161</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.imc.org/ietf-openpgp/mail-archive/msg14307.html">[ietf-openpgp] 20060827 Bleichenbacher's RSA signature forgery based on implementation error</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3793">ADV-2006-3793</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3730">ADV-2006-3730</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3566">ADV-2006-3566</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2006-188.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-188.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.605306">SSA:2006-257-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1016791">1016791</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200609-18.xml">GLSA-200609-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200609-05.xml">GLSA-200609-05</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FREEBSD</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.freebsd.org/advisories/FreeBSD-SA-06:19.openssl.asc">FreeBSD-SA-06:19</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31492">31492</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22259">22259</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22161">22161</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22036">22036</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21982">21982</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21930">21930</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21927">21927</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21906">21906</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21873">21873</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21870">21870</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21852">21852</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21846">21846</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21823">21823</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21812">21812</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21791">21791</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21785">21785</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21778">21778</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21776">21776</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/21767">21767</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771">HPSBMA02250</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495">SSRT061273</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:178">MDKSA-2006:178</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:177">MDKSA-2006:177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc">20060901-01-P</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061213</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://secure-support.novell.com/KanisaPlatform/Publishing/41/3143224_f.SAL_Public.html">https://secure-support.novell.com/KanisaPlatform/Publishing/41/3143224_f.SAL_Public.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-1633">https://issues.rpath.com/browse/RPL-1633</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html">http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html">http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/server/doc/releasenotes_server.html">http://www.vmware.com/support/server/doc/releasenotes_server.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/player2/doc/releasenotes_player2.html">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/player/doc/releasenotes_player.html">http://www.vmware.com/support/player/doc/releasenotes_player.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html">http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html">http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html">http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html">http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vmware.com/security/advisories/VMSA-2008-0005.html">http://www.vmware.com/security/advisories/VMSA-2008-0005.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.sybase.com/detail?id=1047991">http://www.sybase.com/detail?id=1047991</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.serv-u.com/releasenotes/">http://www.serv-u.com/releasenotes/</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/28276">28276</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/22083">22083</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/489739/100/0/threaded">20080318 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/456546/100/200/threaded">20070110 VMware ESX server security updates</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0073.html">RHSA-2007:0073</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0072.html">RHSA-2007:0072</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0062.html">RHSA-2007:0062</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.029-bind.html">OpenPKG-SA-2006.029</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.018.html">OpenPKG-SA-2006.018</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2007_10_ibmjava.html">SUSE-SA:2007:010</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_61_opera.html">SUSE-SA:2006:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2006_26_sr.html">SUSE-SR:2006:026</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:207">MDKSA-2006:207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:178">MDKSA-2006:178</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2006:177">MDKSA-2006:177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200610-06.xml">GLSA-200610-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0905/references">ADV-2008-0905</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/4224">ADV-2007-4224</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/2783">ADV-2007-2783</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/2315">ADV-2007-2315</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/2163">ADV-2007-2163</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1945">ADV-2007-1945</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1815">ADV-2007-1815</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1401">ADV-2007-1401</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/0343">ADV-2007-0343</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/0254">ADV-2007-0254</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/5146">ADV-2006-5146</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4750">ADV-2006-4750</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4744">ADV-2006-4744</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4586">ADV-2006-4586</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4417">ADV-2006-4417</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4366">ADV-2006-4366</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4329">ADV-2006-4329</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4327">ADV-2006-4327</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4216">ADV-2006-4216</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4207">ADV-2006-4207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4206">ADV-2006-4206</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/4205">ADV-2006-4205</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3936">ADV-2006-3936</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3899">ADV-2006-3899</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtml">20061108 Multiple Vulnerabilities in OpenSSL library</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CISCO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_response09186a008077af1b.html">20061108 Multiple Vulnerabilities in OpenSSL Library</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.bluecoat.com/support/knowledge/openSSL_RSA_Signature_forgery.html">http://www.bluecoat.com/support/knowledge/openSSL_RSA_Signature_forgery.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.arkoon.fr/upload/alertes/40AK-2006-04-FR-1.1_SSL360_OPENSSL_RSA.pdf">http://www.arkoon.fr/upload/alertes/40AK-2006-04-FR-1.1_SSL360_OPENSSL_RSA.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.attachmate.com/techdocs/2137.html">http://support.attachmate.com/techdocs/2137.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.attachmate.com/techdocs/2128.html">http://support.attachmate.com/techdocs/2128.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.attachmate.com/techdocs/2127.html">http://support.attachmate.com/techdocs/2127.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201534-1">201534</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201247-1">201247</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200708-1">200708</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102759-1">102759</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102744-1">102744</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102722-1">102722</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102696-1">102696</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102686-1">102686</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102657-1">102657</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102656-1">102656</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1">102648</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.566955">SSA:2006-310-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1017522">1017522</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28115">28115</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26893">26893</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26329">26329</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25649">25649</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25399">25399</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25284">25284</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24950">24950</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24930">24930</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24099">24099</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23915">23915</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23841">23841</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23794">23794</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23680">23680</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23455">23455</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23155">23155</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22949">22949</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22948">22948</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22940">22940</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22939">22939</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22938">22938</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22937">22937</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22936">22936</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22934">22934</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22932">22932</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22799">22799</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22758">22758</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22733">22733</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22711">22711</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22689">22689</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22671">22671</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22585">22585</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22545">22545</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22523">22523</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22513">22513</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22509">22509</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22446">22446</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22325">22325</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22284">22284</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22260">22260</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22232">22232</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22226">22226</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22066">22066</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/22044">22044</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://openvpn.net/changelog.html">http://openvpn.net/changelog.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.theaimsgroup.com/?l=bind-announce&amp;m=116253119512445&amp;w=2">[bind-announce] 20061103 Internet Systems Consortium Security Advisory. [revised]</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.vmware.com/pipermail/security-announce/2008/000008.html">[security-announce] 20080317 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html">APPLE-SA-2007-12-14</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html">APPLE-SA-2006-11-28</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540">HPSBUX02186</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771">HPSBMA02250</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495">SSRT061273</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:207">MDKSA-2006:207</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307177">http://docs.info.apple.com/article.html?artnum=307177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=304829">http://docs.info.apple.com/article.html?artnum=304829</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BEA</vuln:source>
            <vuln:reference xml:lang="en" href="http://dev2dev.bea.com/pub/advisory/238">BEA07-169.00</vuln:reference>
        </vuln:references>
        <vuln:summary>OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.</vuln:summary>
    </entry>
    <entry id="CVE-2006-6731">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update18" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update12" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_18" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update12</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.3.1_18</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.3.1:update18</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-6731</vuln:cve-id>
        <vuln:published-datetime>2006-12-26T18:28:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-20T00:59:35.157-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2006-12-27T14:17:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/939609">VU#939609</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/149457">VU#149457</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA07-022A.html">TA07-022A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/21675">21675</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2006/5073">ADV-2006-5073</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102729-1">102729</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1017425">1017425</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23650">23650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23445">23445</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://scary.beasts.org/security/CESA-2005-008.txt">http://scary.beasts.org/security/CESA-2005-008.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0003.html">SUSE-SA:2007:003</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0073.html">RHSA-2007:0073</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0072.html">RHSA-2007:0072</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0062.html">RHSA-2007:0062</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2007_10_ibmjava.html">SUSE-SA:2007:010</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200705-20.xml">GLSA-200705-20</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/4224">ADV-2007-4224</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1814">ADV-2007-1814</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/0936">ADV-2007-0936</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200702-08.xml">GLSA-200702-08</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200701-15.xml">GLSA-200701-15</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28115">28115</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25404">25404</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25283">25283</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24468">24468</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24189">24189</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24099">24099</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23835">23835</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html">APPLE-SA-2007-12-14</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307177">http://docs.info.apple.com/article.html?artnum=307177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BEA</vuln:source>
            <vuln:reference xml:lang="en" href="http://dev2dev.bea.com/pub/advisory/243">BEA07-174.00</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function.  NOTE: some of these details are obtained from third party information.</vuln:summary>
    </entry>
    <entry id="CVE-2006-6917">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup_server:11.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:ca:brightstor_arcserve_backup_server:11.5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2006-6917</vuln:cve-id>
        <vuln:published-datetime>2006-12-31T00:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-10T01:16:53.563-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-01-12T15:55:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/454094/30/360/threaded">20061211 Re: LS-20060908 - Computer Associates BrightStor ARCserve Backup</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/453933/30/420/threaded">20061211 Re: LS-20061001 - Computer Associates BrightStor ARCserve Backup</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/453933/30/420/threaded">20061211 Re: LS-20061001 - Computer Associates BrightStor ARCserve Backup</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/453930/30/390/threaded">20061208 LS-20060908 - Computer Associates BrightStor ARCserve Backup v11.5 Remote Buffer Overflow Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.lssec.com/advisories/LS-20061001.pdf">http://www.lssec.com/advisories/LS-20061001.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.lssec.com/advisories/LS-20060908.pdf">http://www.lssec.com/advisories/LS-20060908.pdf</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34959">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34959</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97428">http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97428</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/456428/100/0/threaded">20070109 CA BrightStor ARCserve Backup Tape Engine Exploit Security Notice</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/456711">20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.milw0rm.com/exploits/3086">3086</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://supportconnectw.ca.com/public/storage/infodocs/basbrtapeeng-secnotice.asp">http://supportconnectw.ca.com/public/storage/infodocs/basbrtapeeng-secnotice.asp</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MILW0RM</vuln:source>
            <vuln:reference xml:lang="en" href="http://milw0rm.com/exploits/3086">3086</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote attackers to execute arbitrary code in the Tape Engine (tapeeng.exe) via a crafted RPC request with (1) opnum 38, which is not properly handled in TAPEUTIL.dll 11.5.3884.0, or (2) opnum 37, which is not properly handled in TAPEENG.dll 11.5.3884.0.</vuln:summary>
    </entry>
    <entry id="CVE-2007-0099">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:3.0" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
            <vuln:product>cpe:/a:microsoft:xml_core_services:3.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-0099</vuln:cve-id>
        <vuln:published-datetime>2007-01-08T15:28:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-05T00:00:00.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>9.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-01-08T16:05:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:5793" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5793" />
        <vuln:cwe id="CWE-362" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA08-316A.html">TA08-316A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/21872">21872</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MS</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.microsoft.com/technet/security/Bulletin/MS08-069.mspx">MS08-069</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/3111">ADV-2008-3111</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/456343/100/0/threaded">20070104 Re: RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/455986/100/0/threaded">20070104 RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/455965/100/0/threaded">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1021164">1021164</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23655">23655</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://seclists.org/fulldisclosure/2007/Jan/0110.html">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/32627">32627</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://isc.sans.org/diary.php?storyid=2004">http://isc.sans.org/diary.php?storyid=2004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FULLDISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0113.html">20070104 Re: Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</vuln:reference>
        </vuln:references>
        <vuln:summary>Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."</vuln:summary>
    </entry>
    <entry id="CVE-2007-0243">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update16" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update1" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update10" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update11" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update12" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update2" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update4" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update5" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update6" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update7" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update8" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2:update9" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01a" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_16" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_18" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_03" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_08" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_09" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_10" />
                <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9" />
                <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update18" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2_08</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2_09</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.3.1:update18</vuln:product>
            <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2_03</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.3.1:update16</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update8</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update7</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update9</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update4</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update3</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update6</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.3.1_16</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update5</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.3.1_18</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update2</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update1</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update12</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update10</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.4.2:update11</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
            <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.3.1_01a</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.3.1_01</vuln:product>
            <vuln:product>cpe:/a:sun:sdk:1.4.2_10</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-0243</vuln:cve-id>
        <vuln:discovered-datetime>2006-06-16T00:00:00.000-04:00</vuln:discovered-datetime>
        <vuln:published-datetime>2007-01-17T17:28:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-18T01:21:03.000-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-01-18T09:13:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-119" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA07-022A.html">TA07-022A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/388289">VU#388289</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.zerodayinitiative.com/advisories/ZDI-07-005.html">http://www.zerodayinitiative.com/advisories/ZDI-07-005.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1">102760</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/31537">jre-gif-bo(31537)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/22085">22085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/457638/100/0/threaded">20070121 Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability Prove Of Concept Exploit</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/457159/100/0/threaded">20070117 ZDI-07-005: Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0956.html">RHSA-2007:0956</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0167.html">RHSA-2007:0167</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0166.html">RHSA-2007:0166</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2007_45_java.html">SUSE-SA:2007:045</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200702-07.xml">GLSA-200702-07</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/4224">ADV-2007-4224</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1814">ADV-2007-1814</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/0936">ADV-2007-0936</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/0211">ADV-2007-0211</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html">http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html">http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1017520">1017520</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/2158">2158</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200702-08.xml">GLSA-200702-08</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28115">28115</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27203">27203</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26645">26645</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26119">26119</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26049">26049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25283">25283</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24993">24993</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24468">24468</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24202">24202</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/24189">24189</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/23757">23757</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/32834">32834</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html">APPLE-SA-2007-12-14</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307177">http://docs.info.apple.com/article.html?artnum=307177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BEA</vuln:source>
            <vuln:reference xml:lang="en" href="http://dev2dev.bea.com/pub/advisory/242">BEA07-172.00</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</vuln:reference>
        </vuln:references>
        <vuln:summary>Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.</vuln:summary>
    </entry>
    <entry id="CVE-2007-1558">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apop_protocol:apop_protocol" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apop_protocol:apop_protocol</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-1558</vuln:cve-id>
        <vuln:published-datetime>2007-04-16T18:19:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-13T01:34:28.627-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>2.6</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>HIGH</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-04-18T09:30:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA07-151A.html">TA07-151A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/23257">23257</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2007/mfsa2007-15.html">http://www.mozilla.org/security/announce/2007/mfsa2007-15.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1994">ADV-2007-1994</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1939">ADV-2007-1939</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1480">ADV-2007-1480</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1468">ADV-2007-1468</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1467">ADV-2007-1467</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/1466">ADV-2007-1466</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2007/dsa-1305">DSA-1305</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-1424">https://issues.rpath.com/browse/RPL-1424</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-1232">https://issues.rpath.com/browse/RPL-1232</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-1231">https://issues.rpath.com/browse/RPL-1231</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-520-1">USN-520-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-469-1">USN-469-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1018008">1018008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/471842/100/0/threaded">20070620 FLEA-2007-0027-1: thunderbird</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/471720/100/0/threaded">20070619 FLEA-2007-0026-1: evolution-data-server</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/471455/100/0/threaded">20070615 rPSA-2007-0122-1 evolution-data-server</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/470172/100/200/threaded">20070531 FLEA-2007-0023-1: firefox</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/464569/100/0/threaded">20070403 Re: APOP vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/464477/30/0/threaded">20070402 APOP vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2009-1140.html">RHSA-2009:1140</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0402.html">RHSA-2007:0402</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0401.html">RHSA-2007:0401</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0386.html">RHSA-2007:0386</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0385.html">RHSA-2007:0385</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0353.html">RHSA-2007:0353</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0344.html">RHSA-2007:0344</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2009/08/18/1">[oss-security] 20090818 Re: CVE-2007-1558 update (was: mailfilter 0.8.2 fixes CVE-2007-1558 (APOP))</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openwall.com/lists/oss-security/2009/08/15/1">[oss-security] 20090815 mailfilter 0.8.2 fixes CVE-2007-1558 (APOP)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2007_36_mozilla.html">SUSE-SA:2007:036</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2007_14_sr.html">SUSE-SR:2007:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:131">MDKSA-2007:131</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:119">MDKSA-2007:119</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:113">MDKSA-2007:113</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:107">MDKSA-2007:107</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:105">MDKSA-2007:105</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2007/dsa-1300">DSA-1300</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.claws-mail.org/news.php">http://www.claws-mail.org/news.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sylpheed.sraoss.jp/en/news.html">http://sylpheed.sraoss.jp/en/news.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://sourceforge.net/forum/forum.php?forum_id=683706">http://sourceforge.net/forum/forum.php?forum_id=683706</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.571857">SSA:2007-152-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200706-06.xml">GLSA-200706-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35699">35699</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://mail.gnome.org/archives/balsa-list/2007-July/msg00000.html">[balsa-list] 20070704 balsa-2.3.17 released</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579">SSRT061236</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579">SSRT061236</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579">SSRT061236</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579">SSRT061236</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:105">MDKSA-2007:105</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://fetchmail.berlios.de/fetchmail-SA-2007-01.txt">http://fetchmail.berlios.de/fetchmail-SA-2007-01.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=305530">http://docs.info.apple.com/article.html?artnum=305530</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://balsa.gnome.org/download.html">http://balsa.gnome.org/download.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SGI</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc">20070602-01-P</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0082">ADV-2008-0082</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/2788">ADV-2007-2788</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26415">26415</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26083">26083</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25894">25894</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25858">25858</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25798">25798</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25750">25750</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25664">25664</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25559">25559</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25546">25546</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25534">25534</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25529">25529</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25496">25496</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25476">25476</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25402">25402</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25353">25353</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579">SSRT061236</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:summary>The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions.  NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.</vuln:summary>
    </entry>
    <entry id="CVE-2007-2872">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.7" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.2</vuln:product>
            <vuln:product>cpe:/a:php:php:4.4.7</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-2872</vuln:cve-id>
        <vuln:published-datetime>2007-06-04T13:30:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-08T01:32:51.203-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-06-05T08:38:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-189" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/releases/5_2_3.php">http://www.php.net/releases/5_2_3.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.html">FEDORA-2007-2215</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00354.html">FEDORA-2007-709</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://launchpad.net/bugs/173043">https://launchpad.net/bugs/173043</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-1702">https://issues.rpath.com/browse/RPL-1702</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-1693">https://issues.rpath.com/browse/RPL-1693</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39398">php-chunksplit-security-bypass(39398)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2008/0059">ADV-2008-0059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntulinux.org/support/documentation/usn/usn-549-1">USN-549-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-549-2">USN-549-2</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>TRUSTIX</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.trustix.org/errata/2007/0023/">2007-0023</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1018186">1018186</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/24261">24261</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/491693/100/0/threaded">SSRT080056</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/470244/100/0/threaded">20070601 SEC Consult SA-20070601-0 :: PHP chunk_split() integer overflow</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.sec-consult.com/291.html">http://www.sec-consult.com/291.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0891.html">RHSA-2007:0891</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0890.html">RHSA-2007:0890</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0888.html">RHSA-2007:0888</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/releases/4_4_8.php">http://www.php.net/releases/4_4_8.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.php.net/ChangeLog-4.php">http://www.php.net/ChangeLog-4.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OPENPKG</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.020.html">OpenPKG-SA-2007.020</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:187">MDKSA-2007:187</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml">GLSA-200710-02</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/3386">ADV-2007-3386</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/2061">ADV-2007-2061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm">http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.482863">SSA:2007-152-01</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28318">28318</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27864">27864</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27545">27545</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27377">27377</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27351">27351</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27110">27110</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27102">27102</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27037">27037</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26967">26967</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26930">26930</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26895">26895</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26871">26871</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26838">26838</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26231">26231</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26048">26048</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25535">25535</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25456">25456</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://rhn.redhat.com/errata/RHSA-2007-0889.html">RHSA-2007:0889</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html">SUSE-SA:2007:044</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501">SSRT080010</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">SSRT071447</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">SSRT071447</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/491693/100/0/threaded">SSRT080056</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0398">ADV-2008-0398</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SLACKWARE</vuln:source>
            <vuln:reference xml:lang="en" href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.335136">SSA:2008-045-03</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30040">30040</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28936">28936</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28750">28750</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28658">28658</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html">SUSE-SA:2008:004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501">SSRT080010</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.</vuln:summary>
    </entry>
    <entry id="CVE-2007-3285">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt" />
                </cpe-lang:logical-test>
                <cpe-lang:logical-test negate="false" operator="OR">
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:beta1" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:rc2" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:rc3" />
                    <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4" />
                </cpe-lang:logical-test>
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0:rc2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0:rc3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0:beta1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
            <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-3285</vuln:cve-id>
        <vuln:published-datetime>2007-06-20T15:30:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-26T01:02:24.127-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>6.8</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-06-21T10:26:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
        <vuln:cwe id="CWE-264" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.mozilla.org/show_bug.cgi?id=383478">https://bugzilla.mozilla.org/show_bug.cgi?id=383478</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-490-1">USN-490-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1018413">1018413</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/24447">24447</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2007_49_mozilla.html">SUSE-SA:2007:049</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mozilla.org/security/announce/2007/mfsa2007-22.html">http://www.mozilla.org/security/announce/2007/mfsa2007-22.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:152">MDKSA-2007:152</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.0x000000.com/?i=333">http://www.0x000000.com/?i=333</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html">http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26271">26271</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26258">26258</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26216">26216</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26204">26204</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26149">26149</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26072">26072</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>OSVDB</vuln:source>
            <vuln:reference xml:lang="en" href="http://osvdb.org/38032">38032</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt">ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/4256">ADV-2007-4256</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1">201516</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUNALERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1">103177</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28135">28135</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</vuln:reference>
        </vuln:references>
        <vuln:summary>Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.</vuln:summary>
    </entry>
    <entry id="CVE-2007-3593">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:adventnet:manageengine_netflow_analyzer:5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:adventnet:manageengine_netflow_analyzer:5</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-3593</vuln:cve-id>
        <vuln:published-datetime>2007-07-06T14:30:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-10T01:29:45.953-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-07-09T17:29:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/24766">24766</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/25947">25947</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://lostmon.blogspot.com/2007/07/netflow-analizer-5-opmanager-7-multiple.html">http://lostmon.blogspot.com/2007/07/netflow-analizer-5-opmanager-7-multiple.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/35263">netflowanalyzer-opmanager-multiple-xss(35263)</vuln:reference>
        </vuln:references>
        <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML via the (1) alpha parameter in (a) netflow/jspui/applicationList.jsp, the (2) task parameter in (b) netflow/jspui/appConfig.jsp, the (3) view parameter in (c) netflow/jspui/index.jsp, and the (4) rtype parameter in (d) netflow/jspui/selectDevice.jsp and (e) netflow/jspui/customReport.jsp. NOTE: it was later reported that vector 3 also affects 7.5 build 7500.</vuln:summary>
    </entry>
    <entry id="CVE-2007-4465">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.28:beta" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.32:beta" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.34:beta" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.35" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.36" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.37" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.38" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.39" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.40" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.41" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.42" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.43" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.44" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.45" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.49" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.50" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.51" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.52" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.53" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.54" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.55" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.56" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.57" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.58" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.59" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.60" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.61" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.7" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.8" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:2.0.32:beta</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.55</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.56</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.57</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.58</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.59</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.50</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.51</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.52</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.53</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.54</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.6</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.9</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.8</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.7</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.44</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.45</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.49</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.42</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.43</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.40</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.41</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.34:beta</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.32</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.38</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.37</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.39</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.36</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.35</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28:beta</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.28</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.60</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.61</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-4465</vuln:cve-id>
        <vuln:published-datetime>2007-09-13T20:17:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T01:47:12.093-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-09-14T09:40:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:6089" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6089" />
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.us-cert.gov/cas/techalerts/TA08-150A.html">TA08-150A</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/25653">25653</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/479237/100/0/threaded">20070912 Apache2 Undefined Charset UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.apache.org/dist/httpd/CHANGES_2.2.6">http://www.apache.org/dist/httpd/CHANGES_2.2.6</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3113">3113</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASONRES</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/achievement_securityalert/46">20070912 Apache2 Undefined Charset UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33105">33105</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/31651">31651</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">HPSBUX02365</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">HPSBUX02365</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00353.html">FEDORA-2007-707</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/36586">apache-utf7-xss(36586)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-575-1">USN-575-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0008.html">RHSA-2008:0008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0006.html">RHSA-2008:0006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0005.html">RHSA-2008:0005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0004.html">RHSA-2008:0004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-0911.html">RHSA-2007:0911</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html">FEDORA-2007-2214</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2007_61_apache2.html">SUSE-SA:2007:061</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:014">MDVSA-2008:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1697">ADV-2008-1697</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm">http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://securitytracker.com/id?1019194">1019194</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200711-06.xml">GLSA-200711-06</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30430">30430</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28749">28749</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28607">28607</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28471">28471</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28467">28467</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27732">27732</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27563">27563</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26952">26952</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/26842">26842</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html">APPLE-SA-2008-05-28</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.gentoo.org/show_bug.cgi?id=186219">http://bugs.gentoo.org/show_bug.cgi?id=186219</vuln:reference>
        </vuln:references>
        <vuln:summary>Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset.  NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.</vuln:summary>
    </entry>
    <entry id="CVE-2007-5707">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.0" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.1" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.10" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.11" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.12" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.13" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.7" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.8" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:1.2.9" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.0" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.10" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.11" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.11_11" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.11_11s" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.11_9" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.12" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.13" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.14" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.15" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.16" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.17" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.18" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.19" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.20" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.21" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.22" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.23" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.24" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.25" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.26" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.27" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.6" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.7" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.8" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.0.9" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.10" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.11" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.12" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.13" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.14" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.15" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.16" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.17" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.18" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.19" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.20" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.21" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.22" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.23" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.24" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.25" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.26" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.27" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.28" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.29" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.30" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.7" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.8" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1.9" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.1_.20" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.10" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.11" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.12" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.13" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.14" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.15" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.16" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.17" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.18" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.19" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.20" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.21" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.22" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.23" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.24" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.25" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.26" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.27" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.28_r2" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.29_rev_1.134" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.5" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.6" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.7" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.8" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.2.9" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.3.27_2.20061018" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.3.28_2.20061022" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.3.28_20061022" />
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.3.28_e1.0.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openldap:openldap:2.2.20</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.21</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.22</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.23</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.24</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.25</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.26</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.3.28_20061022</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.27</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.30</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1_.20</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.21</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.20</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.23</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.22</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.25</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.24</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.27</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.26</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.11_9</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.3.28_2.20061022</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.19</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.18</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.12</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.17</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.11</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.16</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.10</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.15</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.14</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.29_rev_1.134</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.16</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.13</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.15</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.12</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.14</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.11</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.13</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.10</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.19</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.18</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.17</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.3.28_e1.0.0</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.29</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.26</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.25</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.28</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.27</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.22</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.11_11</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.21</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.24</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.23</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.20</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.9</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.1.1</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.0.3</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.1.0</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.1.3</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.0.1</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.6</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.1.2</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.0.2</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.5</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.8</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.1.4</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.7</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.13</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.2</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.1</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.12</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.11</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.4</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.10</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.3</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2.0</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.11_11s</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.28_r2</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.3.27_2.20061018</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.2</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.1</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.16</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.9</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.15</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.18</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.17</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.6</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.1</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.19</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.5</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.0</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.8</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.7</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.5</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.2</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.4</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:1.0</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.7</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.4</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.10</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.6</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.1.3</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.9</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.12</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.8</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.11</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.14</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.2.13</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.7</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.6</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.9</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.8</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.1</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.0</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.3</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.2</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.5</vuln:product>
            <vuln:product>cpe:/a:openldap:openldap:2.0.4</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-5707</vuln:cve-id>
        <vuln:published-datetime>2007-10-30T15:46:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-17T01:41:10.407-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>7.1</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-10-31T06:21:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/26245">26245</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openldap.org/lists/openldap-announce/200710/msg00001.html">[openldap-announce] 20071026 OpenLDAP 2.3.39 available</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/3645">ADV-2007-3645</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27424">27424</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3184">ADV-2009-3184</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-551-1">USN-551-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1018924">1018924</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/26245">26245</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-1038.html">RHSA-2007:1038</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2007-1037.html">RHSA-2007:1037</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/archives/fedora-package-announce/2007-November/msg00460.html">FEDORA-2007-741</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5119">http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5119</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.novell.com/linux/security/advisories/2007_24_sr.html">SUSE-SR:2007:024</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:215">MDKSA-2007:215</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1541">DSA-1541</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3937">http://support.apple.com/kb/HT3937</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200803-28.xml">GLSA-200803-28</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29682">29682</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29461">29461</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27868">27868</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27756">27756</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27683">27683</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27596">27596</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27587">27587</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html">APPLE-SA-2009-11-09-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=440632">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=440632</vuln:reference>
        </vuln:references>
        <vuln:summary>OpenLDAP before 2.3.39 allows remote attackers to cause a denial of service (slapd crash) via an LDAP request with a malformed objectClasses attribute.  NOTE: this has been reported as a double free, but the reports are inconsistent.</vuln:summary>
    </entry>
    <entry id="CVE-2007-6203">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.46" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.47" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.48" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.49" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.50" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.51" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.52" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.53" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.54" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.55" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.57" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.58" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0.59" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.7" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.1.8" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.2.4" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:2.0.55</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.0</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.57</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.58</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.59</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.50</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.51</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.52</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.53</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.54</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.2.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.6</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.5</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.4</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.8</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.7</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.2</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.1.1</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.46</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.47</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.48</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0.49</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-6203</vuln:cve-id>
        <vuln:published-datetime>2007-12-03T17:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T01:52:50.377-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2007-12-04T11:13:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/38800">apache-413error-xss(38800)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/USN-731-1">USN-731-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019030">1019030</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/26663">26663</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/484410/100/0/threaded">20071130 PR07-37: XSS on Apache HTTP Server 413 error pages via malformed HTTP method</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1875/references">ADV-2008-1875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/4301">ADV-2007-4301</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2007/4060">ADV-2007-4060</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg1PK57952">PK57952</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/34219">34219</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/33105">33105</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30732">30732</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28196">28196</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/27906">27906</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MISC</vuln:source>
            <vuln:reference xml:lang="en" href="http://procheckup.com/Vulnerability_PR07-37.php">http://procheckup.com/Vulnerability_PR07-37.php</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1623/references">ADV-2008-1623</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>AIXAPAR</vuln:source>
            <vuln:reference xml:lang="en" href="http://www-1.ibm.com/support/docview.wss?uid=swg24019245">PK65782</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3411">3411</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200803-19.xml">GLSA-200803-19</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30356">30356</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29640">29640</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29420">29420</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29348">29348</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html">SUSE-SA:2008:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
        </vuln:references>
        <vuln:summary>Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0005">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.3" />
                <cpe-lang:fact-ref name="cpe:/a:apache:http_server:2.0" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:apache:http_server:1.3</vuln:product>
            <vuln:product>cpe:/a:apache:http_server:2.0</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0005</vuln:cve-id>
        <vuln:published-datetime>2008-01-11T19:46:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T01:54:30.797-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.3</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>MEDIUM</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
                <cvss:availability-impact>NONE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-01-14T09:37:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-79" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html">FEDORA-2008-1695</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html">FEDORA-2008-1711</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/39615">apache-modproxyftp-utf7-xss(39615)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-575-1">USN-575-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019185">1019185</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27234">27234</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/505990/100/0/threaded">20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/486167/100/0/threaded">20080110 SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0009.html">RHSA-2008:0009</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0008.html">RHSA-2008:0008</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0007.html">RHSA-2008:0007</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0006.html">RHSA-2008:0006</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0005.html">RHSA-2008:0005</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0004.html">RHSA-2008:0004</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:016">MDVSA-2008:016</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:015">MDVSA-2008:015</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:014">MDVSA-2008:014</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/1875/references">ADV-2008-1875</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm">http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASON</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/securityalert/3526">3526</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SREASONRES</vuln:source>
            <vuln:reference xml:lang="en" href="http://securityreason.com/achievement_securityalert/49">20080110 Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200803-19.xml">GLSA-200803-19</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/35650">35650</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/30732">30732</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29640">29640</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29420">29420</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29348">29348</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28977">28977</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28749">28749</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28607">28607</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28526">28526</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28471">28471</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28467">28467</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>HP</vuln:source>
            <vuln:reference xml:lang="en" href="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.vmware.com/pipermail/security-announce/2009/000062.html">[security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html">SUSE-SA:2008:021</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
        </vuln:references>
        <vuln:summary>mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.</vuln:summary>
    </entry>
    <entry id="CVE-2007-6698">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.3.35" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openldap:openldap:2.3.35</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2007-6698</vuln:cve-id>
        <vuln:published-datetime>2008-02-01T17:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-17T01:43:32.687-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-02-04T10:04:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00105.html">FEDORA-2008-1307</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://bugzilla.redhat.com/show_bug.cgi?id=431203">https://bugzilla.redhat.com/show_bug.cgi?id=431203</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3184">ADV-2009-3184</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019480">1019480</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/26245">26245</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/488242/100/200/threaded">20080212 rPSA-2008-0059-1 openldap openldap-clients openldap-servers</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0110.html">RHSA-2008:0110</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openldap.org/lists/openldap-bugs/200704/msg00068.html">[openldap-bugs] 20070411 Re: (ITS#4925) Modify operation with NOOP control on a BDB backend causes slapd to crash</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MLIST</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openldap.org/lists/openldap-bugs/200704/msg00067.html">[openldap-bugs] 20070411 (ITS#4925) Modify operation with NOOP control on a BDB backend causes slapd to crash</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0059">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/Advisories:rPSA-2008-0059">http://wiki.rpath.com/Advisories:rPSA-2008-0059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3937">http://support.apple.com/kb/HT3937</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29068">29068</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28953">28953</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28817">28817</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html">APPLE-SA-2009-11-09-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-584-1">USN-584-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:058">MDVSA-2008:058</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1541">DSA-1541</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29957">29957</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29682">29682</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29256">29256</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29225">29225</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00011.html">SUSE-SR:2008:010</vuln:reference>
        </vuln:references>
        <vuln:summary>The BDB backend for slapd in OpenLDAP before 2.3.36 allows remote authenticated users to cause a denial of service (crash) via a potentially-successful modify operation with the NOOP control set to critical, possibly due to a double free vulnerability.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0658">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:openldap:openldap:2.3.39" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:openldap:openldap:2.3.39</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0658</vuln:cve-id>
        <vuln:published-datetime>2008-02-13T16:00:00.000-05:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-11-17T01:45:07.750-05:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>4.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
                <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
                <cvss:integrity-impact>NONE</cvss:integrity-impact>
                <cvss:availability-impact>PARTIAL</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-02-14T12:05:00.000-05:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:cwe id="CWE-399" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.vupen.com/english/advisories/2009/3184">ADV-2009-3184</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019481">1019481</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/27778">27778</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/archive/1/archive/1/488242/100/200/threaded">20080212 rPSA-2008-0059-1 openldap openldap-clients openldap-servers</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>REDHAT</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.redhat.com/support/errata/RHSA-2008-0110.html">RHSA-2008:0110</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5358">http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5358</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-bdb/modrdn.c.diff?r1=1.197&amp;r2=1.198&amp;f=h">http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-bdb/modrdn.c.diff?r1=1.197&amp;r2=1.198&amp;f=h</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>VUPEN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.frsirt.com/english/advisories/2008/0536/references">ADV-2008-0536</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0059">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://wiki.rpath.com/Advisories:rPSA-2008-0059">http://wiki.rpath.com/Advisories:rPSA-2008-0059</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="http://support.apple.com/kb/HT3937">http://support.apple.com/kb/HT3937</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29068">29068</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28953">28953</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28926">28926</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/28914">28914</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>APPLE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html">APPLE-SA-2009-11-09-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/40479">openldap-modrdn-dos(40479)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-584-1">USN-584-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>MANDRIVA</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:058">MDVSA-2008:058</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>DEBIAN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.debian.org/security/2008/dsa-1541">DSA-1541</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>GENTOO</vuln:source>
            <vuln:reference xml:lang="en" href="http://security.gentoo.org/glsa/glsa-200803-28.xml">GLSA-200803-28</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29957">29957</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29682">29682</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29461">29461</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29256">29256</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECUNIA</vuln:source>
            <vuln:reference xml:lang="en" href="http://secunia.com/advisories/29225">29225</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SUSE</vuln:source>
            <vuln:reference xml:lang="en" href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00011.html">SUSE-SR:2008:010</vuln:reference>
        </vuln:references>
        <vuln:summary>slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related issue to CVE-2007-6698.</vuln:summary>
    </entry>
    <entry id="CVE-2008-0599">
        <vuln:vulnerable-configuration id="http://nvd.nist.gov">
            <cpe-lang:logical-test negate="false" operator="OR">
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.2" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.3" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.4" />
                <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.5" />
            </cpe-lang:logical-test>
        </vuln:vulnerable-configuration>
        <vuln:vulnerable-software-list>
            <vuln:product>cpe:/a:php:php:5.0.0:rc3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0:rc2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0:rc1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.2.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0:beta2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0:beta1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0:beta4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.0:beta3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
            <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
            <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
        </vuln:vulnerable-software-list>
        <vuln:cve-id>CVE-2008-0599</vuln:cve-id>
        <vuln:published-datetime>2008-05-05T13:20:00.000-04:00</vuln:published-datetime>
        <vuln:last-modified-datetime>2009-10-31T01:56:17.733-04:00</vuln:last-modified-datetime>
        <vuln:cvss>
            <cvss:base_metrics>
                <cvss:score>10.0</cvss:score>
                <cvss:access-vector>NETWORK</cvss:access-vector>
                <cvss:access-complexity>LOW</cvss:access-complexity>
                <cvss:authentication>NONE</cvss:authentication>
                <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
                <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
                <cvss:availability-impact>COMPLETE</cvss:availability-impact>
                <cvss:source>http://nvd.nist.gov</cvss:source>
                <cvss:generated-on-datetime>2008-05-06T10:01:00.000-04:00</cvss:generated-on-datetime>
            </cvss:base_metrics>
        </vuln:cvss>
        <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
        <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" name="oval:org.mitre.oval:def:5510" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5510" />
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CERT-VN</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.kb.cert.org/vuls/id/147027">VU#147027</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00779.html">FEDORA-2008-3606</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>FEDORA</vuln:source>
            <vuln:reference xml:lang="en" href="https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00773.html">FEDORA-2008-3864</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>CONFIRM</vuln:source>
            <vuln:reference xml:lang="en" href="https://issues.rpath.com/browse/RPL-2503">https://issues.rpath.com/browse/RPL-2503</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>XF</vuln:source>
            <vuln:reference xml:lang="en" href="http://xforce.iss.net/xforce/xfdb/42137">php-vector-unspecified(42137)</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>UBUNTU</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.ubuntu.com/usn/usn-628-1">USN-628-1</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>SECTRACK</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securitytracker.com/id?1019958">1019958</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BID</vuln:source>
            <vuln:reference xml:lang="en" href="http://www.securityfocus.com/bid/29009">29009</vuln:reference>
        </vuln:references>
        <vuln:references xml:lang="en" reference_type="UNKNOWN">
            <vuln:source>BUGTRAQ</vuln:source>
            <vuln:reference xml:lang="en" h