<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd" pub_date="2012-05-15T06:10:42" nvd_xml_version="2.0">
  <entry id="CVE-2011-1390">
    <vuln:cve-id>CVE-2011-1390</vuln:cve-id>
    <vuln:published-datetime>2012-05-14T18:55:01.353-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-14T18:55:01.353-04:00</vuln:last-modified-datetime>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/71802" xml:lang="en">rcq-maintenancetool-sql-injection(71802)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-01.ibm.com/support/docview.wss?uid=swg21594717" xml:lang="en">http://www-01.ibm.com/support/docview.wss?uid=swg21594717</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2 allows remote attackers to execute arbitrary SQL commands by leveraging an error in the user-database upgrade feature.</vuln:summary>
  </entry>
  <entry id="CVE-2011-4031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.7.3" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.6" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.5.4" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.4.8" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.5.1" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.7.1" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.4.9_pre1" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.8.1" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.5.3" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.7.2" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.5.2" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.6.2" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.5" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.3.1" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.3" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.4.9:pre1" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.6.1" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.4.7" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.4.6" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.3.4" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.8.0" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.4.0" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.3.2" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.3.3" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.4.4" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.4.5" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.4.2" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.4.3" />
        <cpe-lang:fact-ref name="cpe:/a:ffmpeg:ffmpeg:0.8.2" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.7.3</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.4.8</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.5</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.5.2</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.4.9_pre1</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.3.3</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.8.2</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.7.2</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.4.9:pre1</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.4.5</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.6.2</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.4.7</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.6</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.3.2</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.5.4</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.3.4</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.8.1</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.6.1</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.5.3</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.8.0</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.3</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.3.1</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.4.2</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.5.1</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.4.4</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.7.1</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.4.6</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.4.0</vuln:product>
      <vuln:product>cpe:/a:ffmpeg:ffmpeg:0.4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2011-4031</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T06:33:14.880-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T13:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189" />
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/en-us/security/msvr/msvr11-012" xml:lang="en">http://technet.microsoft.com/en-us/security/msvr/msvr11-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.videolan.org/?p=ffmpeg.git;a=shortlog;h=n0.8.3" xml:lang="en">http://git.videolan.org/?p=ffmpeg.git;a=shortlog;h=n0.8.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://git.videolan.org/?p=ffmpeg.git;a=commit;h=c2a2ad133eb9d42361804a568dee336992349a5e" xml:lang="en">http://git.videolan.org/?p=ffmpeg.git;a=commit;h=c2a2ad133eb9d42361804a568dee336992349a5e</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer underflow in the asfrtp_parse_packet function in libavformat/rtpdec_asf.c in FFmpeg before 0.8.3 allows remote attackers to execute arbitrary code via a crafted ASF packet.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio_viewer:2010" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio_viewer:2010:sp1" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:visio_viewer:2010:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio_viewer:2010</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0018</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.193-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T10:01:15.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T10:00:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-031" xml:lang="en">MS12-031</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "VSD File Format Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2010" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2010:sp1" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2011::mac" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp3" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2010</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2011::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2010:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0141</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.240-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T10:09:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399" />
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-030" xml:lang="en">MS12-030</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel File Format Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2010" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2010:sp1" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2008::mac" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2010</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2010:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2008::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0142</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.273-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T10:25:23.253-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T10:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-030" xml:lang="en">MS12-030</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel File Format Memory Corruption in OBJECTLINK Record Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2008::mac" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2008::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0143</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.320-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T10:27:44.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T10:26:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-030" xml:lang="en">MS12-030</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Memory Corruption Using Various Modified Bytes Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0159">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_8:consumer_preview" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2010" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2010:sp1" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.1.10111.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.60831.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.60531.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.60310.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.60129.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.51204.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.50917.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.50826.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.50524.00" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.50401.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:5.0.61118.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:5.0.60818.0:rc" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:5.0.60401.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:5.0.61118.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.50401.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.51204.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:5.0.60401.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:5.0.60818.0:rc</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.60531.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.1.10111.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.50524.00</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2007:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.60129.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.60831.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.50917.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2010</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x86</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.50826.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_8:consumer_preview</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.60310.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2010:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0159</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.380-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T10:33:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-034" xml:lang="en">MS12-034</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview; Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Silverlight 4 before 4.1.10329; and Silverlight 5 before 5.1.10411 allow remote attackers to execute arbitrary code via a crafted TrueType font (TTF) file, aka "TrueType Font Parsing Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0160">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.0:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5:sp1" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5.1" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0160</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.427-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T11:07:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-035" xml:lang="en">MS12-035</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0161">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1:sp1" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.0:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5:sp1" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:3.5.1" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:3.5:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0161</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.477-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T11:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-035" xml:lang="en">MS12-035</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0162</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.507-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T11:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-034" xml:lang="en">MS12-034</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft .NET Framework 4 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Buffer Allocation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0164">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:4.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0164</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.537-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T12:10:24.600-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T12:10:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-034" xml:lang="en">MS12-034</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft .NET Framework 4 does not properly compare index values, which allows remote attackers to cause a denial of service (application hang) via crafted requests to a Windows Presentation Foundation (WPF) application, aka ".NET Framework Index Comparison Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0165">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2010" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2010:sp1" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2010</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2007:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2010:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0165</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.583-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T12:22:33.367-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T12:20:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-034" xml:lang="en">MS12-034</vuln:reference>
    </vuln:references>
    <vuln:summary>GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0167">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007:sp2" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2007:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0167</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.617-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T12:24:35.347-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T12:23:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-034" xml:lang="en">MS12-034</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka "GDI+ Heap Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0174">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-:sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7:-:sp1:x86" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7:-:sp1:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0174</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.647-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T12:42:08.847-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T12:39:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-032" xml:lang="en">MS12-032</vuln:reference>
    </vuln:references>
    <vuln:summary>Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly enforce firewall rules for outbound broadcast packets, which allows remote attackers to obtain potentially sensitive information by observing broadcast traffic on a local network, aka "Windows Firewall Bypass Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.603310.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.60831.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.50401.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.1.10111.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.1.10111" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.50524.00" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.50826.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.50917.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.51204.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.60531.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.60310.0" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:silverlight:4.0.60129.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:silverlight:4.1.10111</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.50917.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.60531.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.50826.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.50524.00</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.1.10111.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.50401.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.60129.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.51204.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.60310.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.60831.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:silverlight:4.0.603310.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0176</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.677-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T12:48:11.177-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T12:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-034" xml:lang="en">MS12-034</vuln:reference>
    </vuln:references>
    <vuln:summary>Double free vulnerability in Microsoft Silverlight 4 before 4.1.10329 on Windows allows remote attackers to execute arbitrary code via vectors involving crafted XAML glyphs, aka "Silverlight Double-Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0178">
    <vuln:cve-id>CVE-2012-0178</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.727-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-08T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T12:54:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-033" xml:lang="en">MS12-033</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that makes multiple simultaneous Plug and Play (PnP) Configuration Manager function calls, aka "Plug and Play (PnP) Configuration Manager Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0179">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0179</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.757-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T13:01:19.950-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T12:58:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-032" xml:lang="en">MS12-032</vuln:reference>
    </vuln:references>
    <vuln:summary>Double free vulnerability in tcpip.sys in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that binds an IPv6 address to a local interface, aka "TCP/IP Double Free Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0180">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::itanium" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0180</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.803-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T13:04:59.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T13:04:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-034" xml:lang="en">MS12-034</vuln:reference>
    </vuln:references>
    <vuln:summary>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode for (1) windows and (2) messages, which allows local users to gain privileges via a crafted application, aka "Windows and Messages Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0181">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:-:sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:-:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0181</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.833-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T13:11:17.207-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T13:06:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-034" xml:lang="en">MS12-034</vuln:reference>
    </vuln:references>
    <vuln:summary>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout File Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0183">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2003:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2007:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2007:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2008::mac" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp3" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:word:2007:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2008::mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0183</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.867-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T13:13:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-029" xml:lang="en">MS12-029</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0184">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2010" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2010:sp1" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2008" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2011::mac" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp3" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2010</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2011::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2010:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2008</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0184</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.913-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T13:24:54.233-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T13:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-030" xml:lang="en">MS12-030</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SXLI Record Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0185">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2010" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2010:sp1" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp3" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2010</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2010:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0185</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.943-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T13:27:42.170-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T13:26:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-030" xml:lang="en">MS12-030</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka "Excel MergeCells Record Heap Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-0649">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0649</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:58.730-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T09:33:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-362" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in the initialization routine in blued in Bluetooth in Apple Mac OS X before 10.7.4 allows local users to gain privileges via vectors involving a temporary file.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0651">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.8" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0651</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:58.777-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T09:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain sensitive information from process memory via a crafted message.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0652">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.3" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0652</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:58.840-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T09:53:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Login Window in Apple Mac OS X 10.7.3, when Legacy File Vault or networked home directories are enabled, does not properly restrict what is written to the system log for network logins, which allows local users to obtain sensitive information by reading the log.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0654">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0654</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:58.887-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T09:57:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>libsecurity in Apple Mac OS X before 10.7.4 accesses uninitialized memory locations during the processing of X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted certificate.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0655">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0655</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:58.933-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T10:22:44.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T10:04:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-310" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within X.509 certificates, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by conducting a spoofing or network-sniffing attack during communication with a site that uses a short key.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0656">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.3" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0656</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:58.980-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T10:12:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-362" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in LoginUIFramework in Apple Mac OS X 10.7.x before 10.7.4, when the Guest account is enabled, allows physically proximate attackers to login to arbitrary accounts by entering the account name and no password.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0657">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0657</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:59.027-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T10:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Quartz Composer in Apple Mac OS X before 10.7.4, when the RSS Visualizer screensaver is enabled, allows physically proximate attackers to bypass screen locking and launch a Safari process via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0658">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0658</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:59.077-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T10:18:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted audio sample tables in a movie file that is progressively downloaded.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0659">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0659</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:59.107-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T10:29:55.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T10:27:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0660">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0660</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:59.137-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T10:28:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0661">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.2" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.1" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0661</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:59.200-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T10:36:58.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T10:35:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in QuickTime in Apple Mac OS X 10.7.x before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0662">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0662</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:59.263-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T10:44:08.230-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T10:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted input.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0672">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0.1:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0.1:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.2:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.2:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.2.1:-:ipad" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.1:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.1:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.1.3:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.1.2:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.0:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.5:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.5:-:ipad" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0:-:ipad" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0.1:-:ipad" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0.1:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0.1:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.1:-:ipad" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.1:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.1:-:ipodtouch" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.1:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.0:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.1.2:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0.1:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0.1:-:ipad</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.1:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0.1:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.2:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0:-:ipad</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.1:-:ipad</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.1.3:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.2.1:-:ipad</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.5:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.2:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.5:-:ipad</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0672</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T06:25:46.957-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T23:44:32.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-08T08:11:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5282" xml:lang="en">http://support.apple.com/kb/HT5282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00002.html" xml:lang="en">APPLE-SA-2012-05-09-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00000.html" xml:lang="en">APPLE-SA-2012-05-07-1</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit in Apple iOS before 5.1.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0674">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0.1:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0.1:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.2:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.2:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.2.1:-:ipad" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.1:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.1:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.1.3:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.1.2:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:3.0:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.5:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:4.3.5:-:ipad" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0:-:ipad" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0.1:-:ipad" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0.1:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.0.1:-:ipodtouch" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.1:-:ipad" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.1:-:iphone" />
        <cpe-lang:fact-ref name="cpe:/o:apple:iphone_os:5.1:-:ipodtouch" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.1:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.0:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.1.2:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0.1:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0.1:-:ipad</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.1:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0.1:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.2:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.1:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0:-:ipad</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.0:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:5.1:-:ipad</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.1.3:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.2.1:-:ipad</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.0:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.5:-:ipodtouch</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:3.2:-:iphone</vuln:product>
      <vuln:product>cpe:/o:apple:iphone_os:4.3.5:-:ipad</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0674</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T06:25:47.020-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-08T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-08T08:21:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00000.html" xml:lang="en">APPLE-SA-2012-05-07-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Safari in Apple iOS before 5.1.1 allows remote attackers to spoof the location bar's URL via a crafted web site.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0675">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.7.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.6.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.5.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.11" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.10" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.4" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.0" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.2" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0.3" />
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.10</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.7.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.7.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.6.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.6.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0675</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:59.293-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T10:48:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5281" xml:lang="en">http://support.apple.com/kb/HT5281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" xml:lang="en">APPLE-SA-2012-05-09-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Time Machine in Apple Mac OS X before 10.7.4 does not require continued use of SRP-based authentication after this authentication method is first used, which allows remote attackers to read Time Capsule credentials by spoofing the backup volume.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0676">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.1.6" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.1.5" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.1.4" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.1.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.1.3" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.1.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.0.5" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.0.6" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:5.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.1.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.5" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.1.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.0b" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:4.0:beta" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.1:beta" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.2.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.1.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.1.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.1b" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.1:-:mac" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.0b:-:windows" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.2.1b:-:windows" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.0b" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.2.0b:-:windows" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.0:-:mac" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.1.2b:-:windows" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.1.1b:-:windows" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.3:-:mac" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.3b" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.3b:-:windows" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.4:-:mac" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.2.2b:-:windows" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.1b:-:windows" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.2.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.2:-:mac" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.2.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.2b" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.2b:-:windows" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.1.0b" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.1.0b:-:windows" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.4b" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.0.4b:-:windows" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.1.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:3.1.0:-:mac" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0.4:-:mac" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0.3:417.9.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0.3:417.9.3" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0.3:417.8" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0.3:417.9" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.3.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.2.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.1.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0b1:-:mac" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0.0b2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.3.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0.0b1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.2.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.2.2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.2.3" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.2.4" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.2.5" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.3" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.3.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0:beta2" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0:beta" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0.3:85.8" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.0.3:85.8.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.1.1" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.3.2:312.5" />
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:1.3.2:312.6" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:1.3.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.2.2b:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:safari:2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.1.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0b1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.2.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.4:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.1.5</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.2.1b:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.4b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:2.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:2.0.3:417.9.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.1.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0:beta</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.1.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.2b:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.1.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.2b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.2.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.1b:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:safari:2.0.4:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.2.0b:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:safari:2.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0.3:85.8.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.3.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.2.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.3.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.1.1b:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.1b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.1:beta</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.2.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:2.0.3:417.9</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.0b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.0b:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.3b:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.0.6</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.1.0b:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.2.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:2.0.3:417.9.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:2.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0.0b2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.2.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:2.0.3:417.8</vuln:product>
      <vuln:product>cpe:/a:apple:safari:5.1.6</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.4b:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:safari:2.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.5</vuln:product>
      <vuln:product>cpe:/a:apple:safari:2.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.3b</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.3:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.1.2b:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:safari:2.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.2.5</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0:beta2</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.3.2:312.6</vuln:product>
      <vuln:product>cpe:/a:apple:safari:3.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.3.2:312.5</vuln:product>
      <vuln:product>cpe:/a:apple:safari:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0.0</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0.0b1</vuln:product>
      <vuln:product>cpe:/a:apple:safari:1.0.3:85.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0676</vuln:cve-id>
    <vuln:published-datetime>2012-05-10T23:49:59.340-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T11:05:28.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T10:56:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT5282" xml:lang="en">http://support.apple.com/kb/HT5282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2012/May/msg00002.html" xml:lang="en">APPLE-SA-2012-05-09-2</vuln:reference>
    </vuln:references>
    <vuln:summary>WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing of form input, which allows remote attackers to fill in form fields on the pages of arbitrary web sites via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0684">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.30" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.25:a" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.25" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.24" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.23" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.22" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.21" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.20" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.40" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.37" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.36" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.35" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.34" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.33" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.32" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.31" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.60" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.61" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.50.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.55" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.46" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.50" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.41" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.45" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.70.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.70.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.68.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.70" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.67" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.68" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.65" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.66" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.05" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.04" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.05:c" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.05:b" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.01" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.0:a" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.03" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.02" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.10" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.11" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.12" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.13" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.06" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.07" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.08" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.09" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.17:a" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.18" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.18.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.19" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.14" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.15" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.16" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.17" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.97" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.97.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.95.4" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.96" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.95.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.95.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.96.5" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.97.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.96.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.96.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.82.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.82.4" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.90" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.90.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.90.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.70.4" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.74" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.80" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.80.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.80.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.80.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.82" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.82.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.93.4" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.93.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.94" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.93.6" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.94.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.94.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.95.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.95" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91.4" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91.6" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91.5" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.93" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.97.4" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.92" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.93.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.93.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.92.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.98.4" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xnview:xnview:1.20</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.21</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.92.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.08</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.12</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.82.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.18</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.80.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.70.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.50.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.25:a</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.94.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.05:b</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.82.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.70.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91.5</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.41</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.97</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.94</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.95.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.93</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.80.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.13</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.35</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.96.5</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.98.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.97.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.30</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.11</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.61</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.95</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.67</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.19</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.96.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.10</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.04</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.70.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.24</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.07</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.90.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.80.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.90</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.94.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.18.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.60</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.16</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.92</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.93.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.0:a</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.82.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.22</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.46</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.96</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.32</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.80</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.05:c</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.74</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.93.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.31</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.93.6</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.96.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.40</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.66</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.03</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.34</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.36</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.06</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.37</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.93.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.95.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.90.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.65</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.02</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.14</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.09</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.97.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.01</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.17</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.97.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.05</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.33</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91.6</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.17:a</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.23</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.68</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.15</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.82</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.25</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.50</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.93.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.95.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.68.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.95.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.55</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.45</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0684</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T06:33:14.927-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T13:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189" />
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/en-us/security/msvr/msvr12-001" xml:lang="en">http://technet.microsoft.com/en-us/security/msvr/msvr12-001</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0685.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0685">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.30" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.25:a" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.25" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.24" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.23" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.22" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.21" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.20" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.40" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.37" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.36" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.35" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.34" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.33" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.32" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.31" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.60" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.61" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.50.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.55" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.46" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.50" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.41" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.45" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.70.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.70.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.68.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.70" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.67" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.68" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.65" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.66" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.05" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.04" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.05:c" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.05:b" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.01" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.0:a" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.03" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.02" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.10" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.11" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.12" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.13" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.06" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.07" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.08" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.09" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.17:a" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.18" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.18.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.19" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.14" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.15" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.16" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.17" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.97" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.97.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.95.4" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.96" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.95.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.95.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.96.5" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.97.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.96.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.96.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.82.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.82.4" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.90" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.90.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.90.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.70.4" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.74" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.80" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.80.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.80.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.80.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.82" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.82.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.93.4" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.93.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.94" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.93.6" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.94.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.94.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.95.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.95" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91.4" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91.3" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91.6" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.91.5" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.93" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.97.4" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.92" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.93.2" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.93.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.92.1" />
        <cpe-lang:fact-ref name="cpe:/a:xnview:xnview:1.98.4" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xnview:xnview:1.20</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.21</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.92.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.08</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.12</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.82.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.18</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.80.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.70.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.50.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.25:a</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.94.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.05:b</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.82.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.70.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91.5</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.41</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.97</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.94</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.95.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.93</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.80.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.13</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.35</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.96.5</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.98.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.97.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.30</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.11</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.61</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.95</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.67</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.19</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.96.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.10</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.04</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.70.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.24</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.07</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.90.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.80.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.90</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.94.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.18.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.60</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.16</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.92</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.93.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.0:a</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.82.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.22</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.46</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.96</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.32</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.80</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.05:c</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.74</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.93.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.31</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.93.6</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.96.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.40</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.66</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.03</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.34</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.36</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.06</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.37</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.93.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.95.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.90.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.65</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.02</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.14</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.09</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.97.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.01</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.17</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.97.4</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.05</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.33</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.91.6</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.17:a</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.23</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.68</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.15</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.82</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.25</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.50</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.93.3</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.95.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.68.1</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.95.2</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.55</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.45</vuln:product>
      <vuln:product>cpe:/a:xnview:xnview:1.70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0685</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T06:33:14.957-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T13:16:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189" />
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/en-us/security/msvr/msvr12-001" xml:lang="en">http://technet.microsoft.com/en-us/security/msvr/msvr12-001</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0684.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0778">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_cs3:9.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_cs4:10.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_cs5.5:11.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:flash_cs4:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_cs5.5:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_cs3:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0778</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:39.057-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T13:38:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-12.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-12.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Adobe Flash Professional before CS6 allows attackers to execute arbitrary code via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2012-0780">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator_cs5.5:15" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:15.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:9.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:12.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:11.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:8.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:7.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:10.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:11.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:14.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:illustrator:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator_cs5.5:15</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:12.0.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:15.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:14.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-0780</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:39.087-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-14T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T13:55:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-10.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-10.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.</vuln:summary>
  </entry>
  <entry id="CVE-2012-1675">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_11g" />
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_11g:11.1.0.7" />
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_11g:11.2.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_11g:11.2.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_10g" />
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_10g:10.2.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_10g:10.2.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_10g:10.2.0.5" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_10g:10.2.0.4</vuln:product>
      <vuln:product>cpe:/a:oracle:database_11g:11.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:database_10g</vuln:product>
      <vuln:product>cpe:/a:oracle:database_11g:11.2.0.3</vuln:product>
      <vuln:product>cpe:/a:oracle:database_11g</vuln:product>
      <vuln:product>cpe:/a:oracle:database_11g:11.1.0.7</vuln:product>
      <vuln:product>cpe:/a:oracle:database_10g:10.2.0.3</vuln:product>
      <vuln:product>cpe:/a:oracle:database_10g:10.2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-1675</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T18:55:01.010-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T09:37:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264" />
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/359816" xml:lang="en">VU#359816</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://blogs.oracle.com/security/entry/security_alert_for_cve_2012" xml:lang="en">https://blogs.oracle.com/security/entry/security_alert_for_cve_2012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/75303" xml:lang="en">oracledatabase-tnslistener-spoofing(75303)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1027000" xml:lang="en">1027000</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/53308" xml:lang="en">53308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/fulldisclosure/2012/Apr/343" xml:lang="en">20120428 Oracle TNS Poison vulnerability is actually a 0day with no patch available</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/fulldisclosure/2012/Apr/204" xml:lang="en">20120418 The history of a -probably- 13 years old Oracle bug: TNS Poison</vuln:reference>
    </vuln:references>
    <vuln:summary>The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison."</vuln:summary>
  </entry>
  <entry id="CVE-2012-1804">
    <vuln:cve-id>CVE-2012-1804</vuln:cve-id>
    <vuln:published-datetime>2012-05-14T16:55:01.417-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-14T16:55:01.417-04:00</vuln:last-modified-datetime>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/control_systems/pdf/ICSA-12-131-01.pdf" xml:lang="en">http://www.us-cert.gov/control_systems/pdf/ICSA-12-131-01.pdf</vuln:reference>
    </vuln:references>
    <vuln:summary>Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.</vuln:summary>
  </entry>
  <entry id="CVE-2012-1823">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.11" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.10" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.9" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.8" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.7" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.6" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.5" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.5" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.11" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.8" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.6" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.9" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.12" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.13" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.17" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.10" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.7" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.15" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.16" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.14" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc2" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:5.2.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.17</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.13</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.10</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.7</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.15</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.14</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.12</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.8</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.11</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.16</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.9</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-1823</vuln:cve-id>
    <vuln:published-datetime>2012-05-11T06:15:48.043-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T11:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20" />
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/520827" xml:lang="en">VU#520827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.php.net/bug.php?id=61910" xml:lang="en">https://bugs.php.net/bug.php?id=61910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-5.php#5.4.2" xml:lang="en">http://www.php.net/ChangeLog-5.php#5.4.2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.php.net/patch-display.php?bug_id=61910&amp;patch=cgi.diff&amp;revision=1335984315&amp;display=1" xml:lang="en">https://bugs.php.net/patch-display.php?bug_id=61910&amp;patch=cgi.diff&amp;revision=1335984315&amp;display=1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/archive/2012.php#id2012-05-03-1" xml:lang="en">http://www.php.net/archive/2012.php#id2012-05-03-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/" xml:lang="en">http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/</vuln:reference>
    </vuln:references>
    <vuln:summary>sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.</vuln:summary>
  </entry>
  <entry id="CVE-2012-1847">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007:sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007:sp3" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2010" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2010:sp1" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2008" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2011::mac" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp2" />
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office_compatibility_pack::sp3" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2010</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2011::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2010:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:office_compatibility_pack::sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2008</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-1847</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:01.977-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T13:29:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-030" xml:lang="en">MS12-030</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Series Record Parsing Type Mismatch Could Result in Remote Code Execution Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-1848">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp3" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2:itanium" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::sp2:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x86" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008::sp2:itanium" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x86" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_7::sp1:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2::itanium" />
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008:r2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2008::sp2:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x86</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_7::sp1:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-1848</vuln:cve-id>
    <vuln:published-datetime>2012-05-08T20:55:02.007-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T13:34:23.910-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T13:33:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://technet.microsoft.com/security/bulletin/MS12-034" xml:lang="en">MS12-034</vuln:reference>
    </vuln:references>
    <vuln:summary>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Scrollbar Calculation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2012-1977">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:wellintech:kingview:3.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wellintech:kingview:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-1977</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T06:33:15.020-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T12:41:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/control_systems/pdf/ICSA-12-129-01.pdf" xml:lang="en">http://www.us-cert.gov/control_systems/pdf/ICSA-12-129-01.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://dsecrg.com/pages/vul/show.php?id=405" xml:lang="en">http://dsecrg.com/pages/vul/show.php?id=405</vuln:reference>
    </vuln:references>
    <vuln:summary>WellinTech KingSCADA 3.0 uses a cleartext base64 format for storage of passwords in user.db, which allows context-dependent attackers to obtain sensitive information by reading this file.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:performance_insight:5.3" />
        <cpe-lang:fact-ref name="cpe:/a:hp:performance_insight:5.41" />
        <cpe-lang:fact-ref name="cpe:/a:hp:performance_insight:5.41.002" />
        <cpe-lang:fact-ref name="cpe:/a:hp:performance_insight:5.41.001" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:performance_insight:5.41.002</vuln:product>
      <vuln:product>cpe:/a:hp:performance_insight:5.41.001</vuln:product>
      <vuln:product>cpe:/a:hp:performance_insight:5.3</vuln:product>
      <vuln:product>cpe:/a:hp:performance_insight:5.41</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2007</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T06:33:15.207-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T11:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03312417" xml:lang="en">SSRT100853</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03312417" xml:lang="en">HPSBMU02775</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:performance_insight:5.3" />
        <cpe-lang:fact-ref name="cpe:/a:hp:performance_insight:5.41" />
        <cpe-lang:fact-ref name="cpe:/a:hp:performance_insight:5.41.002" />
        <cpe-lang:fact-ref name="cpe:/a:hp:performance_insight:5.41.001" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:performance_insight:5.41.002</vuln:product>
      <vuln:product>cpe:/a:hp:performance_insight:5.41.001</vuln:product>
      <vuln:product>cpe:/a:hp:performance_insight:5.3</vuln:product>
      <vuln:product>cpe:/a:hp:performance_insight:5.41</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2008</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T06:33:15.257-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T11:17:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03312417" xml:lang="en">HPSBMU02775</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03312417" xml:lang="en">SSRT100853</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:performance_insight:5.3" />
        <cpe-lang:fact-ref name="cpe:/a:hp:performance_insight:5.41" />
        <cpe-lang:fact-ref name="cpe:/a:hp:performance_insight:5.41.002" />
        <cpe-lang:fact-ref name="cpe:/a:hp:performance_insight:5.41.001" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:performance_insight:5.41.002</vuln:product>
      <vuln:product>cpe:/a:hp:performance_insight:5.41.001</vuln:product>
      <vuln:product>cpe:/a:hp:performance_insight:5.3</vuln:product>
      <vuln:product>cpe:/a:hp:performance_insight:5.41</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2009</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T06:33:15.303-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T10:43:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03312417" xml:lang="en">SSRT100853</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03312417" xml:lang="en">HPSBMU02775</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote authenticated users to gain privileges via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator_cs5.5:15" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:15.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:9.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:12.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:11.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:8.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:7.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:10.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:11.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:14.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:illustrator:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator_cs5.5:15</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:12.0.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:15.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:14.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2023</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:39.150-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T14:15:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-10.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-10.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator_cs5.5:15" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:15.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:9.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:12.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:11.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:8.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:7.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:10.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:11.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:14.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:illustrator:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator_cs5.5:15</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:12.0.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:15.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:14.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2024</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:39.197-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T14:17:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-10.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-10.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2025, and CVE-2012-2026.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator_cs5.5:15" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:15.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:9.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:12.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:11.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:8.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:7.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:10.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:11.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:14.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:illustrator:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator_cs5.5:15</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:12.0.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:15.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:14.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2025</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:39.243-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T14:18:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-10.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-10.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2026.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator_cs5.5:15" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:15.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:9.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:12.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:11.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:13.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:8.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:7.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:10.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:11.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:illustrator:14.0" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:illustrator:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator_cs5.5:15</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:12.0.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:15.0</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:13.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:illustrator:14.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2026</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:40.183-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T14:20:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-10.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-10.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2025.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop_cs4:11.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop_cs5.5:12.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:9.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:9.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:9.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:8.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:7.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:7.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:6.0::pro" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:6.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:6.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:5.0::pro" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:4.0::pro" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:3.0::pro" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:2.5::pro" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:12.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:12.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:12.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:12.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:12.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:11.0::%7E%7E%7E%7Ex64%7E" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:11.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:11.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:11.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:11.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:10.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:photoshop:12.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:11.0::%7E%7E%7E%7Ex64%7E</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:5.0::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop_cs5.5:12.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop_cs4:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:6.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:11.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:12.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:12.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:12.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:12.0.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:9.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:4.0::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:2.5::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:3.0::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:6.0::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:9.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2027</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:41.167-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T14:24:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-11.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-11.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/52634" xml:lang="en">52634</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Adobe Photoshop before CS6 allows remote attackers to execute arbitrary code via a crafted TIFF (aka .TIF) file.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop_cs4:11.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop_cs5.5:12.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:9.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:9.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:9.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:8.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:7.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:7.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:6.0::pro" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:6.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:6.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:5.0::pro" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:4.0::pro" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:3.0::pro" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:2.5::pro" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:12.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:12.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:12.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:12.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:12.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:11.0::%7E%7E%7E%7Ex64%7E" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:11.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:11.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:11.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:11.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:10.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop:10.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:photoshop" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:photoshop:12.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:11.0::%7E%7E%7E%7Ex64%7E</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:11.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:5.0::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop_cs5.5:12.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop_cs4:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:6.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:10.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:11.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:11.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:12.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:12.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:12.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:12.0.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:9.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:4.0::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:10.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:11.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:2.5::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:3.0::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:6.0::pro</vuln:product>
      <vuln:product>cpe:/a:adobe:photoshop:9.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2028</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:41.213-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-14T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T14:36:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-11.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-11.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Adobe Photoshop before CS6 allows remote attackers to execute arbitrary code via a crafted TIFF (aka .TIF) file.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.0.626" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.2.602" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.9.615" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.7.609" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.8.612" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.10.620" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:1.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.0.11" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:2.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:3.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:4.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.1.601" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:5.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:6.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.6.606" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.0.0.456" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.1.629" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.321" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.3.633" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.324" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.204" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.205" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9.0.383" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.100" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.323" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.325" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.196" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.196a" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.0.3.471" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.023" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.022" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.021" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.4.020" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9.0.432" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.0.595" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.106" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.105" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.0.596" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.103" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.1.016" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.0.011" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.0.1.004" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.9.620" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.0.0.210" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.4.634" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.9.620</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.0.626</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.321</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.0.011</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.2.602</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.0.11</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:3.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.6.606</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.1.016</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.10.620</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:1.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.205</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.196a</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.4.020</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.023</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.323</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.0.1.004</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.022</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.196</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:5.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.324</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.3.633</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.9.615</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.4.634</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.325</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.105</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.8.612</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.0.0.210</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:4.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9.0.383</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.204</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.021</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.0.595</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.7.609</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.100</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.0.0.456</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.1.629</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9.0.432</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.1.601</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.103</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.0.596</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:2.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.0.3.471</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.106</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2029</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:41.243-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T14:40:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-13.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-13.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2030, CVE-2012-2031, CVE-2012-2032, and CVE-2012-2033.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.0.626" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.2.602" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.9.615" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.7.609" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.8.612" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.10.620" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:1.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.0.11" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:2.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:3.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:4.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.1.601" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:5.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:6.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.6.606" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.0.0.456" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.1.629" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.321" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.3.633" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.324" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.204" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.205" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9.0.383" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.100" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.323" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.325" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.196" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.196a" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.0.3.471" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.023" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.022" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.021" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.4.020" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9.0.432" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.0.595" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.106" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.105" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.0.596" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.103" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.1.016" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.0.011" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.0.1.004" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.9.620" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.0.0.210" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.4.634" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.9.620</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.0.626</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.321</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.0.011</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.2.602</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.0.11</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:3.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.6.606</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.1.016</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.10.620</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:1.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.205</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.196a</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.4.020</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.023</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.323</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.0.1.004</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.022</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.196</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:5.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.324</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.3.633</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.9.615</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.4.634</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.325</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.105</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.8.612</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.0.0.210</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:4.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9.0.383</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.204</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.021</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.0.595</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.7.609</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.100</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.0.0.456</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.1.629</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9.0.432</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.1.601</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.103</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.0.596</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:2.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.0.3.471</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.106</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2030</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:41.277-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T14:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-13.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-13.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2031, CVE-2012-2032, and CVE-2012-2033.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.0.626" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.2.602" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.9.615" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.7.609" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.8.612" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.10.620" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:1.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.0.11" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:2.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:3.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:4.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.1.601" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:5.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:6.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.6.606" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.0.0.456" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.1.629" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.321" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.3.633" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.324" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.204" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.205" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9.0.383" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.100" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.323" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.325" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.196" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.196a" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.0.3.471" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.023" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.022" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.021" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.4.020" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9.0.432" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.0.595" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.106" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.105" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.0.596" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.103" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.1.016" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.0.011" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.0.1.004" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.9.620" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.0.0.210" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.4.634" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.9.620</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.0.626</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.321</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.0.011</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.2.602</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.0.11</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:3.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.6.606</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.1.016</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.10.620</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:1.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.205</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.196a</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.4.020</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.023</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.323</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.0.1.004</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.022</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.196</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:5.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.324</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.3.633</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.9.615</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.4.634</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.325</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.105</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.8.612</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.0.0.210</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:4.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9.0.383</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.204</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.021</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.0.595</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.7.609</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.100</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.0.0.456</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.1.629</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9.0.432</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.1.601</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.103</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.0.596</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:2.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.0.3.471</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.106</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2031</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:41.323-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T14:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-13.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-13.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2032, and CVE-2012-2033.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2032">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.0.626" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.2.602" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.9.615" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.7.609" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.8.612" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.10.620" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:1.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.0.11" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:2.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:3.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:4.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.1.601" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:5.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:6.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.6.606" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.0.0.456" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.1.629" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.321" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.3.633" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.324" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.204" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.205" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9.0.383" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.100" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.323" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.325" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.196" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.196a" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.0.3.471" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.023" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.022" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.021" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.4.020" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9.0.432" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.0.595" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.106" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.105" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.0.596" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.103" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.1.016" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.0.011" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.0.1.004" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.9.620" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.0.0.210" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.4.634" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.9.620</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.0.626</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.321</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.0.011</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.2.602</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.0.11</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:3.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.6.606</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.1.016</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.10.620</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:1.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.205</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.196a</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.4.020</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.023</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.323</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.0.1.004</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.022</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.196</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:5.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.324</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.3.633</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.9.615</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.4.634</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.325</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.105</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.8.612</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.0.0.210</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:4.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9.0.383</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.204</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.021</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.0.595</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.7.609</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.100</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.0.0.456</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.1.629</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9.0.432</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.1.601</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.103</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.0.596</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:2.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.0.3.471</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.106</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2032</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:41.387-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T14:46:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-13.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-13.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, and CVE-2012-2033.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.0.626" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.2.602" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.9.615" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.7.609" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.8.612" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.10.620" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:1.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.0.11" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:2.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:3.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:4.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.1.601" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:5.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:6.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.6.606" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.0.0.456" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.1.629" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.321" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.3.633" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.324" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.204" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.205" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9.0.383" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.100" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.323" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.325" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.196" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.0.196a" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.0.3.471" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.023" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.022" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.2.0.021" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.4.020" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:9.0.432" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.0.595" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.106" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.105" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.0.596" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:8.5.1.103" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.1.016" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.1.0.011" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.0.1.004" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.5.9.620" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:10.0.0.210" />
        <cpe-lang:fact-ref name="cpe:/a:adobe:shockwave_player:11.6.4.634" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.9.620</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.0.626</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.321</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.0.011</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.2.602</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.0.11</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:3.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.6.606</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.1.016</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.10.620</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:1.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.205</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.196a</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.1.4.020</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.023</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.323</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.0.1.004</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.022</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.196</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:5.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.324</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.3.633</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.9.615</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.4.634</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.325</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.105</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.8.612</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.0.0.210</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:4.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9.0.383</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.0.204</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:10.2.0.021</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.0.595</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.7.609</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.100</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.0.0.456</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.6.1.629</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9.0.432</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.1.601</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.103</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:9</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.5.0.596</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:2.0</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:11.0.3.471</vuln:product>
      <vuln:product>cpe:/a:adobe:shockwave_player:8.5.1.106</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2033</vuln:cve-id>
    <vuln:published-datetime>2012-05-09T00:36:41.417-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-09T14:47:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb12-13.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb12-13.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, and CVE-2012-2032.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2276">
    <vuln:cve-id>CVE-2012-2276</vuln:cve-id>
    <vuln:published-datetime>2012-05-14T18:55:01.510-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-14T18:55:01.510-04:00</vuln:last-modified-datetime>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/522682" xml:lang="en">20120510 ESA-2012-019: EMC Documentum Information Rights Management Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="http://www.exploit-db.com/exploits/18734" xml:lang="en">18734</vuln:reference>
    </vuln:references>
    <vuln:summary>The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS fields or (2) has an invalid version number.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2277">
    <vuln:cve-id>CVE-2012-2277</vuln:cve-id>
    <vuln:published-datetime>2012-05-14T18:55:01.570-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-14T18:55:01.570-04:00</vuln:last-modified-datetime>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/522682" xml:lang="en">20120510 ESA-2012-019: EMC Documentum Information Rights Management Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="http://www.exploit-db.com/exploits/18734" xml:lang="en">18734</vuln:reference>
    </vuln:references>
    <vuln:summary>The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of many "batch begin untethered" commands.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2311">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.12" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.11" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.10" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.8" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.6" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.5" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.7" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.9" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.5" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.11" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.8" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.6" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.9" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.12" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.13" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.17" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.10" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.7" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.15" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.16" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.14" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.5" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.6" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.7" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.8" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.8" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.9" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta_4_patch1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.11" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.10" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.13" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.12" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.18" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.4" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.3" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.15" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.14" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.17" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.16" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.9" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.7" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.8" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.5" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.6" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:2.0b10" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:2.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:1.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.0:beta2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.2" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:5.2.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.14</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.8</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.9</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.4.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
      <vuln:product>cpe:/a:php:php:2.0b10</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.11</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.10</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.12</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.12</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.17</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.13</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.17</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.13</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.15</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.12</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.14</vuln:product>
      <vuln:product>cpe:/a:php:php:5.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.15</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.8</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.16</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.9</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.11</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta_4_patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.16</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.9</vuln:product>
      <vuln:product>cpe:/a:php:php:2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.8</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.18</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2311</vuln:cve-id>
    <vuln:published-datetime>2012-05-11T06:15:48.107-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T11:27:08.793-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T11:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89" />
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/520827" xml:lang="en">VU#520827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.php.net/patch-display.php?bug_id=61910&amp;patch=cgi.diff-fix-check.patch&amp;revision=1336093719&amp;display=1" xml:lang="en">https://bugs.php.net/patch-display.php?bug_id=61910&amp;patch=cgi.diff-fix-check.patch&amp;revision=1336093719&amp;display=1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.php.net/bug.php?id=61910" xml:lang="en">https://bugs.php.net/bug.php?id=61910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-5.php#5.4.3" xml:lang="en">http://www.php.net/ChangeLog-5.php#5.4.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/archive/2012.php#id2012-05-08-1" xml:lang="en">http://www.php.net/archive/2012.php#id2012-05-08-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/" xml:lang="en">http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/</vuln:reference>
    </vuln:references>
    <vuln:summary>sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2329">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.2" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:5.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2329</vuln:cve-id>
    <vuln:published-datetime>2012-05-11T06:15:48.263-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T11:30:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119" />
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=820000" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=820000</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.php.net/bug.php?id=61807" xml:lang="en">https://bugs.php.net/bug.php?id=61807</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-5.php#5.4.3" xml:lang="en">http://www.php.net/ChangeLog-5.php#5.4.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/archive/2012.php#id2012-05-08-1" xml:lang="en">http://www.php.net/archive/2012.php#id2012-05-08-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2333">
    <vuln:cve-id>CVE-2012-2333</vuln:cve-id>
    <vuln:published-datetime>2012-05-14T18:55:03.070-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-14T18:55:03.070-04:00</vuln:last-modified-datetime>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=820686" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=820686</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openssl.org/news/secadv_20120510.txt" xml:lang="en">http://www.openssl.org/news/secadv_20120510.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.cert.fi/en/reports/2012/vulnerability641549.html" xml:lang="en">http://www.cert.fi/en/reports/2012/vulnerability641549.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.openssl.org/chngview?cn=22547" xml:lang="en">http://cvs.openssl.org/chngview?cn=22547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.openssl.org/chngview?cn=22538" xml:lang="en">http://cvs.openssl.org/chngview?cn=22538</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2335">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.12" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.2" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:5.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2335</vuln:cve-id>
    <vuln:published-datetime>2012-05-11T06:15:48.480-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-11T12:13:32.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T12:12:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264" />
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/520827" xml:lang="en">VU#520827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugs.php.net/bug.php?id=61910" xml:lang="en">https://bugs.php.net/bug.php?id=61910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.php.net/archive/2012.php#id2012-05-06-1" xml:lang="en">http://www.php.net/archive/2012.php#id2012-05-06-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://git.php.net/?p=php-src.git;a=blob;f=sapi/cgi/cgi_main.c;h=a7ac26f0#l1569" xml:lang="en">http://git.php.net/?p=php-src.git;a=blob;f=sapi/cgi/cgi_main.c;h=a7ac26f0#l1569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/" xml:lang="en">http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/</vuln:reference>
    </vuln:references>
    <vuln:summary>php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c component and a query string beginning with a +- sequence.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2336">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.3.13" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.0" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.0:beta2" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.1" />
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.4.2" />
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:5.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.4.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.3.13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2012-2336</vuln:cve-id>
    <vuln:published-datetime>2012-05-11T06:15:48.527-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-14T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2012-05-11T12:18:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20" />
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.php.net/patch-display.php?bug_id=61910&amp;patch=CVE-2012-1823.patch&amp;revision=1336251592&amp;display=1" xml:lang="en">https://bugs.php.net/patch-display.php?bug_id=61910&amp;patch=CVE-2012-1823.patch&amp;revision=1336251592&amp;display=1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugs.php.net/bug.php?id=61910" xml:lang="en">https://bugs.php.net/bug.php?id=61910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-5.php#5.4.3" xml:lang="en">http://www.php.net/ChangeLog-5.php#5.4.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/archive/2012.php#id2012-05-08-1" xml:lang="en">http://www.php.net/archive/2012.php#id2012-05-08-1</vuln:reference>
    </vuln:references>
    <vuln:summary>sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2511">
    <vuln:cve-id>CVE-2012-2511</vuln:cve-id>
    <vuln:published-datetime>2012-05-15T00:21:43.330-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-15T00:21:43.330-04:00</vuln:last-modified-datetime>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://service.sap.com/sap/support/notes/1687910" xml:lang="en">https://service.sap.com/sap/support/notes/1687910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities" xml:lang="en">http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://scn.sap.com/docs/DOC-8218" xml:lang="en">http://scn.sap.com/docs/DOC-8218</vuln:reference>
    </vuln:references>
    <vuln:summary>The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2512">
    <vuln:cve-id>CVE-2012-2512</vuln:cve-id>
    <vuln:published-datetime>2012-05-15T00:21:43.407-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-15T00:21:43.407-04:00</vuln:last-modified-datetime>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://service.sap.com/sap/support/notes/1687910" xml:lang="en">https://service.sap.com/sap/support/notes/1687910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities" xml:lang="en">http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://scn.sap.com/docs/DOC-8218" xml:lang="en">http://scn.sap.com/docs/DOC-8218</vuln:reference>
    </vuln:references>
    <vuln:summary>The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2513">
    <vuln:cve-id>CVE-2012-2513</vuln:cve-id>
    <vuln:published-datetime>2012-05-15T00:21:43.453-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-15T00:21:43.453-04:00</vuln:last-modified-datetime>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://service.sap.com/sap/support/notes/1687910" xml:lang="en">https://service.sap.com/sap/support/notes/1687910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities" xml:lang="en">http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://scn.sap.com/docs/DOC-8218" xml:lang="en">http://scn.sap.com/docs/DOC-8218</vuln:reference>
    </vuln:references>
    <vuln:summary>The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2514">
    <vuln:cve-id>CVE-2012-2514</vuln:cve-id>
    <vuln:published-datetime>2012-05-15T00:21:43.500-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-15T00:21:43.500-04:00</vuln:last-modified-datetime>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://service.sap.com/sap/support/notes/1687910" xml:lang="en">https://service.sap.com/sap/support/notes/1687910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities" xml:lang="en">http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://scn.sap.com/docs/DOC-8218" xml:lang="en">http://scn.sap.com/docs/DOC-8218</vuln:reference>
    </vuln:references>
    <vuln:summary>The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2611">
    <vuln:cve-id>CVE-2012-2611</vuln:cve-id>
    <vuln:published-datetime>2012-05-15T00:21:43.547-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-15T00:21:43.547-04:00</vuln:last-modified-datetime>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://service.sap.com/sap/support/notes/1687910" xml:lang="en">https://service.sap.com/sap/support/notes/1687910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities" xml:lang="en">http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://scn.sap.com/docs/DOC-8218" xml:lang="en">http://scn.sap.com/docs/DOC-8218</vuln:reference>
    </vuln:references>
    <vuln:summary>The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execute arbitrary code via a crafted SAP Diag packet.</vuln:summary>
  </entry>
  <entry id="CVE-2012-2612">
    <vuln:cve-id>CVE-2012-2612</vuln:cve-id>
    <vuln:published-datetime>2012-05-15T00:21:43.597-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-05-15T00:21:43.597-04:00</vuln:last-modified-datetime>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://service.sap.com/sap/support/notes/1687910" xml:lang="en">https://service.sap.com/sap/support/notes/1687910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities" xml:lang="en">http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://scn.sap.com/docs/DOC-8218" xml:lang="en">http://scn.sap.com/docs/DOC-8218</vuln:reference>
    </vuln:references>
    <vuln:summary>The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.</vuln:summary>
  </entry>
</nvd>
